Executive Summary
In September 2026, threat actors compromised legitimate Ukrainian business websites to inject fake Cloudflare verification pages as part of a ClickFix campaign distributing Psychedelic Stealer malware. The attack targeted various Ukrainian businesses including healthcare facilities, retailers, and manufacturers, using social engineering to trick victims into executing malicious MSI installers that harvested browser credentials, cryptocurrency wallets, and account tokens. Arctic Wolf Labs documented 557 views with 426 clicks across the campaign, primarily targeting Ukrainian users but also affecting victims in the US, Poland, Germany, Canada, and the Netherlands.
This incident highlights the growing sophistication of information stealer campaigns that exploit trusted brand impersonation and legitimate website compromise to bypass security controls. The emergence of new stealer families like Psychedelic, combined with advanced evasion techniques and modular malware ecosystems, represents an escalating threat to credential security and highlights the urgent need for enhanced egress filtering and behavioral monitoring capabilities.
Why This Matters Now
Information stealer campaigns are rapidly evolving with new families like Psychedelic demonstrating advanced persistence mechanisms and browser extension manipulation capabilities that traditional security controls struggle to detect and prevent.
Attack Path Analysis
Attackers compromised legitimate Ukrainian business websites to inject fake Cloudflare verification pages that delivered ClickFix lures, tricking users into executing malicious MSI installers that deployed Psychedelic Stealer. The stealer harvested browser credentials, tokens, and cryptocurrency wallet data while establishing persistence through scheduled tasks and browser extensions. Stolen data was exfiltrated through multiple API endpoints to attacker-controlled C2 servers, enabling credential theft and potential financial fraud.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers compromised multiple legitimate Ukrainian business websites and injected malicious iframe elements executing attacker-controlled JavaScript from fsputnik[.]com/tds/tracker[.]js to display fake Cloudflare verification pages with ClickFix lures
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Command and Scripting Interpreter: PowerShell
System Binary Proxy Execution: Msiexec
Credentials from Password Stores: Credentials from Web Browsers
Scheduled Task/Job: Scheduled Task
Abuse Elevation Control Mechanism: Bypass User Account Control
Impair Defenses: Disable or Modify Tools
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Cryptography for Authentication Credentials
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.02(b)
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
CISA ZTMM 2.0 – Software platforms and applications within the organization are inventoried
Control ID: ID.AM-2
NIS2 Directive – Risk Analysis and Information System Security Policies
Control ID: Article 21(2)(a)
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Retail Industry
Ukrainian retail businesses directly compromised in ClickFix campaign, exposing customer payment data and browser credentials to Psychedelic stealer malware targeting PCI compliance requirements.
Health Care / Life Sciences
Healthcare facilities like psychological clinics compromised, risking HIPAA-protected patient data through credential theft and browser session hijacking via malicious Cloudflare verification pages.
Automotive
Automotive retailers specifically targeted in campaign, facing credential theft and cryptocurrency wallet compromise while struggling with east-west traffic security and zero trust implementation gaps.
Publishing Industry
Specialist publishers and booksellers directly affected by website compromise, exposing intellectual property and customer data through browser extension manipulation and native messaging bridge exploitation.
Sources
- Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealerhttps://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.htmlVerified
- Psychedelic Stealer: Fake ClickFix Captcha Targets Ukrainehttps://arcticwolf.com/resources/blog/psychedelic-stealer-fake-clickfix-captcha-targets-ukraine/Verified
- RemotePanel and BoundSiphon: A Dual-Payload Toolkit for Persistent Access and Browser Thefthttps://blackpointcyber.com/blog/remotepanel-and-boundsiphon-a-dual-payload-toolkit-for-persistent-access-and-browser-theft/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this credential theft campaign by constraining lateral movement between workloads and limiting egress paths for data exfiltration. The segmented architecture could contain the impact scope even after initial browser compromise.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust fabric visibility could provide early detection of anomalous web traffic patterns and malicious iframe injection activity across cloud-hosted business websites
Control: Zero Trust Segmentation
Mitigation: Zero Trust segmentation would likely limit the scope of elevated privileges by restricting administrative access to isolated workload segments rather than broad system-wide access
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain cross-browser process injection and limit malicious extension deployment by restricting inter-workload communication paths between browser instances
Control: Multicloud Visibility & Control
Mitigation: Comprehensive visibility controls would likely detect and constrain C2 communication patterns by monitoring API endpoint access and identifying suspicious polling behaviors across cloud workloads
Control: Egress Security & Policy Enforcement
Mitigation: Egress policy enforcement would likely constrain data exfiltration by blocking unauthorized API calls to external endpoints and limiting outbound data transfer volumes
While credential theft may still occur within compromised endpoints, the constrained lateral movement and limited exfiltration paths would likely reduce the overall victim count and scope of financial impact
Impact at a Glance
Affected Business Functions
- Customer Relations and Communications
- E-commerce Operations
- Financial Services
- Professional Services Operations
Estimated downtime: 3 days
Estimated loss: $150,000
Browser credentials including login passwords for Chromium-based browsers, account tokens, cryptocurrency wallet data from MetaMask, Trust Wallet, OKX Wallet, SafePal, Exodus, Atomic Wallet, Electrum, Bitcoin Core, and Litecoin Core. Host system information and potential access to password manager data. Primary impact on Ukrainian businesses including healthcare, retail, publishing, and automotive sectors.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Inline IPS (Suricata) to detect and block malicious JavaScript injection patterns and known ClickFix payload signatures at compromised websites
- • Deploy Egress Security & Policy Enforcement to prevent unauthorized data exfiltration to external C2 servers and block communication with suspicious domains like fsputnik[.]com
- • Enable Multicloud Visibility & Control to monitor anomalous browser extension installations, suspicious API endpoint communications, and detect repeated credential harvesting attempts
- • Establish Zero Trust Segmentation with least privilege policies to limit the impact of compromised browser processes and prevent lateral movement across user profiles
- • Activate Threat Detection & Anomaly Response capabilities to identify unusual MSI installer executions, UAC bypass attempts, and baseline deviations in browser behavior patterns



