Ukrainian Business Sites Compromised to Spread Psychedelic Info-Stealer via Fake Cloudflare Pages

An active ClickFix campaign has compromised legitimate Ukrainian business websites, injecting fake Cloudflare verification pages to trick visitors. When a visitor interacts with the page, a Windows Installer command is copied to the clipboard, and the victim is instructed to paste and run it, leading to the download of a previously undocumented information stealer called Psychedelic.
This campaign leverages trusted Ukrainian business domains as a launchpad, replacing expected content with a deceptive Cloudflare-style verification screen. The attack relies on social engineering: users are prompted to copy a command and execute it manually, bypassing typical browser-based defenses. Once run, the Windows Installer payload delivers Psychedelic, a previously unseen info-stealer designed to harvest sensitive data from compromised systems.
The use of legitimate sites adds credibility, making the fake verification page harder to question. ClickFix-style tactics have grown common, but this instance pairs them with a novel malware family, suggesting evolving tooling among threat actors. The targeting of Ukrainian businesses also hints at geopolitical dimensions, though the campaign’s full scope remains unclear.
This incident could affect Ukrainian businesses and their customers, potentially exposing credentials, financial data, or internal systems. Because the attack rides on trusted domains, even cautious users may fall victim, eroding confidence in online verification processes. The broader impact may include increased scrutiny of Cloudflare-style prompts and heightened awareness of clipboard-based attack chains. Organizations in conflict zones may face added operational strain, while cybersecurity teams could see a rise in similar hybrid social-engineering and malware campaigns.