Compromised Ukrainian Websites Serve Fake Cloudflare Pages to Deploy “Psychedelic” Information Stealer
What Happened — A new ClickFix campaign is hijacking legitimate Ukrainian business sites, replacing their landing pages with counterfeit Cloudflare verification screens. When a visitor clicks “I’m not a robot,” the page copies a Windows‑Installer command to the clipboard and urges the user to paste it, delivering an undocumented information‑stealer dubbed Psychedelic.
Why It Matters for Trust & Control Assurance
- This attack illustrates the risk of third‑party web assets being weaponised against your users – a scenario a continuous control‑assurance program is built to detect and evidence.
- Demonstrates the need for ongoing vendor‑risk monitoring and immutable proof that external sites remain uncompromised, supporting defensible audit trails.
- Highlights the importance of logging and alerting on anomalous content changes and clipboard‑copy commands, which map to a single control objective across many frameworks.
Who Is Affected – Primarily Ukrainian enterprises across sectors (finance, retail, SaaS) whose public‑facing domains were compromised; any organisation whose customers may visit those sites.
Recommended Actions
- Add all public‑facing domains to a third‑party asset inventory and enable continuous integrity monitoring.
- Deploy web‑application firewalls or content‑security‑policy headers that block unexpected clipboard‑copy scripts.
- Incorporate the detection of fake verification pages into your security‑awareness training and incident‑response playbooks.
- Collect and retain change‑log evidence for each external site to satisfy audit‑readiness requirements.
Source: The Hacker News
Technical Notes — The lure injects a bogus Cloudflare “I’m not a robot” page that, on interaction, copies a PowerShell‑style installer command (msiexec /i …) to the clipboard. The command pulls the Psychedelic stealer, a new Windows Installer payload that harvests credentials, browser data, and crypto‑wallet files. No CVE is involved; the vector is a supply‑chain compromise of web hosting environments.