ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer
Brief
Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals browser and crypto credentials.
Psychedelic Stealer is being distributed through compromised Ukrainian business websites. Attackers injected hidden iframes into legitimate pages and used them to display a fake Cloudflare verification screen to visitors. The affected sites included a hair-treatment clinic, a scale-model manufacturer, a specialist bookseller, a psychological facility, a tool retailer, and an automotive retailer.
These were legitimate businesses with established social media profiles and third-party listings. Visitors were therefore directed to a trusted website they may have visited before, making the fake Cloudflare CAPTCHA harder to recognize.
That’s the core of what makes this campaign uncomfortable to dismiss.
