← Back to news

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

The Hacker News24/09/2026, 14:29••
Read full article →

Summary

AI-Generated

Key Points:

  • An active ClickFix campaign is compromising legitimate Ukrainian business websites to distribute the Psychedelic Stealer, which harvests sensitive data and maintains persistence.
  • The attack impacts various Ukrainian businesses, utilizing fake Cloudflare verification pages to lure victims into executing a malicious MSI installer that retrieves the stealer malware.
  • Recommended actions include monitoring for unusual website behavior, implementing strong endpoint protection, and educating users about phishing tactics.

Technical Details: The Psychedelic Stealer is delivered via an MSI installer using the "msiexec.exe" command and communicates with a C2 server for further instructions. The malware can execute various payloads and harvest sensitive information such as browser passwords and cryptocurrency wallet data.

MITRE ATT&CK Techniques:

  • T1566 - Phishing (Initial Access)
  • T1203 - User Execution (Execution)
  • T1059.001 - Command and Scripting Interpreter: PowerShell (Execution)
  • T1547.001 - Boot or Logon Autostart Execution: Scheduled Task (Persistence)
  • T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)

IOCs Mentioned:

  • Domains: fsputnik[.]com, uasputnik[.]com
  • IP Address: 107.175.82[.]242, 193.178.159[.]128
  • Malware Names: Psychedelic Stealer, RemotePanel, BoundSiphon

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.