Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Compromised Ukrainian Websites Serve Fake Cloudflare Pages to Deploy “Psychedelic” Information Stealer

Legitimate Ukrainian business sites have been hijacked to display counterfeit Cloudflare verification pages that deliver the previously unknown Psychedelic information‑stealer. The campaign underscores the need for continuous third‑party monitoring and audit‑ready evidence of web‑asset integrity.

LiveThreat™ Intelligence · 📅 September 25, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

Compromised Ukrainian Websites Serve Fake Cloudflare Pages to Deploy “Psychedelic” Information Stealer

What Happened — A new ClickFix campaign is hijacking legitimate Ukrainian business sites, replacing their landing pages with counterfeit Cloudflare verification screens. When a visitor clicks “I’m not a robot,” the page copies a Windows‑Installer command to the clipboard and urges the user to paste it, delivering an undocumented information‑stealer dubbed Psychedelic.

Why It Matters for Trust & Control Assurance

  • This attack illustrates the risk of third‑party web assets being weaponised against your users – a scenario a continuous control‑assurance program is built to detect and evidence.
  • Demonstrates the need for ongoing vendor‑risk monitoring and immutable proof that external sites remain uncompromised, supporting defensible audit trails.
  • Highlights the importance of logging and alerting on anomalous content changes and clipboard‑copy commands, which map to a single control objective across many frameworks.

Who Is Affected – Primarily Ukrainian enterprises across sectors (finance, retail, SaaS) whose public‑facing domains were compromised; any organisation whose customers may visit those sites.

Recommended Actions

  • Add all public‑facing domains to a third‑party asset inventory and enable continuous integrity monitoring.
  • Deploy web‑application firewalls or content‑security‑policy headers that block unexpected clipboard‑copy scripts.
  • Incorporate the detection of fake verification pages into your security‑awareness training and incident‑response playbooks.
  • Collect and retain change‑log evidence for each external site to satisfy audit‑readiness requirements.

Source: The Hacker News

Technical Notes — The lure injects a bogus Cloudflare “I’m not a robot” page that, on interaction, copies a PowerShell‑style installer command (msiexec /i …) to the clipboard. The command pulls the Psychedelic stealer, a new Windows Installer payload that harvests credentials, browser data, and crypto‑wallet files. No CVE is involved; the vector is a supply‑chain compromise of web hosting environments.

📰 Original Source
https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →