Fake Cloudflare ClickFix pages target Ukrainian visitors with Psychedelic Stealer

Compromised Ukrainian business websites are being used to display counterfeit Cloudflare verification pages that deliver a previously undocumented information stealer named Psychedelic. Arctic Wolf Labs identified 557 views, 426 clicks and 79 completed events in the campaign’s exposed lure-management panel; Ukraine accounted for 446 views, 351 clicks and 71 complete events.
The campaign targets visitors through Ukrainian-language ClickFix instructions. It affects legitimate sites including a hair-treatment clinic, scale-model manufacturer, specialist bookseller and publisher, psychological facility, tool retailer and automotive retailer. The reporting indicates the operation was heavily focused on Ukrainian users, while records also included the United States, Poland, Germany, Canada and the Netherlands.
How the fake verification flow delivers malware
Injected iframe elements on the compromised sites execute attacker-controlled JavaScript from fsputnik[.]com/tds/tracker[.]js. Before showing instructions, the fake verification page copies a Windows Installer command to the visitor’s clipboard. After a three-second spinner, it tells the visitor to open the Windows Run dialog and paste the command.
The page keeps its Done button disabled for about 35 more seconds, but that delay only controls the lure interface. It does not establish whether a victim opened Windows Run, pasted the command or installed the payload. The command uses msiexec.exe to retrieve an MSI installer from uasputnik[.]com, a domain registered on September 9, 2026. Arctic Wolf observed installer names including elita.msi, miks.msi, astra.msi, harbor.msi, neon.msi, sova.msi and vyse.msi.
The MSI downloads psychedeliclove.exe from 107.175.82[.]242:9000. That 64-bit executable, Psychedelic Stealer, collects credentials from Chromium-based browsers such as Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Vivaldi and Yandex. It also gathers browser account tokens, searches for cryptocurrency-wallet extensions and desktop wallet applications, and sends host information to its command-and-control infrastructure.
Browser changes and follow-on execution
Psychedelic Stealer does more than collect data once. It can terminate selected browser processes, extract an embedded extension archive into browser profiles and configure a native-messaging bridge. A recurring routine returns to extension-related operations before polling the command-and-control server, making browser-component handling part of its ongoing execution cycle.
The malware can request further work through an agent task endpoint using a unique hardware identifier. Those tasks can run EXE, COM, BAT, CMD, MSI and PowerShell payloads, giving operators a route to introduce additional malware after the initial compromise. The campaign’s Rublevka TDS panel is distinct from the implant’s command-and-control server: it configures lure commands and polls visitor records every two seconds, providing visibility into page progression rather than endpoint execution.
The technique aligns with the ClickFix chains outlined in ClickFix attack chains and execution risks, where social engineering turns user interaction into the execution mechanism rather than exploiting a browser vulnerability directly. Russian-language branding and implementation artifacts led Arctic Wolf to assess likely Russian operators, although the reporting does not name a specific group.
Separate ClickFix chain delivers RemotePanel and BoundSiphon
Blackpoint Cyber also described a separate ClickFix operation distributing two undocumented .NET components: RemotePanel, a persistent remote-access platform, and BoundSiphon, a credential and cryptocurrency stealer. The campaign begins with a PowerShell command and includes abuse of the CMSTPLUA COM object to bypass User Account Control and launch a privileged hidden PowerShell process.
That process configures broad Microsoft Defender exclusions before delivering RemotePanel to disk as a service and loading BoundSiphon into memory. RemotePanel masquerades as the Windows Time service and offers PowerShell, file and process management, screen access, modular hidden virtual network computing and fleet-management functions. It uses a BNB Smart Chain contract to resolve its command-and-control server, allowing infrastructure changes without rebuilding the implant.
BoundSiphon targets Chromium and Firefox credentials and sessions, wallet data, password-manager information and selected documents. Blackpoint said it can recover secrets protected by Chromium App-Bound Encryption through legitimate Chromium processes. For businesses, the practical control is straightforward: staff should never paste commands into Windows Run, PowerShell or a terminal because a web page claims to be a verification check, and security teams should investigate such prompts on otherwise trusted sites.

