MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-24 · via The Hacker News

Ukrainian Business Sites Compromised to Spread Psychedelic Info-Stealer via Fake Cloudflare Pages

Image via The Hacker News
Image via The Hacker News

An active ClickFix campaign has compromised legitimate Ukrainian business websites, injecting fake Cloudflare verification pages to trick visitors. When a visitor interacts with the page, a Windows Installer command is copied to the clipboard, and the victim is instructed to paste and run it, leading to the download of a previously undocumented information stealer called Psychedelic.

Expanded Detail

This campaign leverages trusted Ukrainian business domains as a launchpad, replacing expected content with a deceptive Cloudflare-style verification screen. The attack relies on social engineering: users are prompted to copy a command and execute it manually, bypassing typical browser-based defenses. Once run, the Windows Installer payload delivers Psychedelic, a previously unseen info-stealer designed to harvest sensitive data from compromised systems.

The use of legitimate sites adds credibility, making the fake verification page harder to question. ClickFix-style tactics have grown common, but this instance pairs them with a novel malware family, suggesting evolving tooling among threat actors. The targeting of Ukrainian businesses also hints at geopolitical dimensions, though the campaign’s full scope remains unclear.

Context

This incident could affect Ukrainian businesses and their customers, potentially exposing credentials, financial data, or internal systems. Because the attack rides on trusted domains, even cautious users may fall victim, eroding confidence in online verification processes. The broader impact may include increased scrutiny of Cloudflare-style prompts and heightened awareness of clipboard-based attack chains. Organizations in conflict zones may face added operational strain, while cybersecurity teams could see a rise in similar hybrid social-engineering and malware campaigns.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
Developer documentation placeholder domain weaponized for ClickFix malware campaign · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer.” Browse more stories.