Threat actors have actively compromised legitimate Ukrainian business websites to distribute a previously unknown information stealer called Psychedelic. The attack uses a well-established social engineering technique known as ClickFix, which deceives visitors into executing malicious Windows Installer commands.

The campaign operates by injecting fake Cloudflare verification pages into hacked Ukrainian sites. When users interact with these pages, the lure automatically copies a malicious Windows Installer command to the clipboard. The page then instructs visitors to paste the command into their systems, creating a false sense of legitimacy by mimicking Cloudflare's actual verification process. This approach exploits user trust in recognized security brands to bypass defenses.

ClickFix attacks have grown increasingly common over the past two years. The technique leverages social engineering rather than technical exploits, making it effective against organizations that maintain strong patch management. Attackers target users directly through compromised websites, avoiding the need to discover vulnerabilities in widely-deployed software. The Cloudflare impersonation adds an extra layer of deception, as users naturally expect verification prompts when accessing certain web properties.

Psychedelic represents a new entry in the information stealer category. The malware collects sensitive data from infected systems, though the full scope of its capabilities remains under analysis. Information stealers typically target credentials, browser data, cryptocurrency wallets, and personal information that criminals can monetize through underground markets or use for follow-up attacks like targeted ransomware campaigns.

The targeting of Ukrainian infrastructure reflects ongoing geopolitical tensions and the country's status as a frequent target for cybercriminal activity. Ukrainian websites across various business sectors make attractive compromise points because they host legitimate traffic and benefit from user trust. Attackers compromise these sites through various methods including unpatched vulnerabilities, weak credentials, and supply chain attacks targeting content management systems or plugins.

Organizations hosting websites should implement several defensive measures. Regular security audits can identify website compromises before attackers deploy malicious content. Web application firewalls can detect and block injection attempts. Content Security Policy headers restrict what code executes on compromised pages. Server-side request forgery protections and input validation prevent attackers from injecting malicious JavaScript or HTML.

End users should treat unexpected verification requests with skepticism, even from recognizable brands like Cloudflare. Legitimate verification pages rarely request Windows commands executed in terminals. Hovering over links to verify URLs and checking browser address bars for legitimate domains provides additional protection. Running security software capable of detecting information stealers adds a detection layer, though social engineering attacks primarily rely on user behavior rather than technical flaws.

The emergence of Psychedelic adds to the growing toolkit of information stealers actively distributed through ClickFix campaigns. Organizations in Ukraine and those conducting business with Ukrainian entities should heighten awareness of this threat. Endpoint detection and response platforms should receive samples of Psychedelic for signature development. The campaign demonstrates how attackers continue adapting social engineering techniques to leverage compromised infrastructure and impersonate trusted services.