Back to News
Cybersecurity

New Psychedelic Stealer Campaign Exploits Ukrainian Websites to Spread Malware

Ukrainian business sites are being compromised to deliver a novel information stealer through deceptive Cloudflare pages.

An alarming ClickFix campaign has been detected, targeting legitimate Ukrainian business websites to distribute a new information stealer known as Psychedelic. The operation involves the injection of counterfeit Cloudflare verification pages designed to mislead users into executing malicious downloads. When users interact with these fraudulent pages, the lure effectively copies a Windows Installer command to their clipboard, prompting unsuspecting victims to paste and execute it, thereby facilitating the malware installation.

For businesses, this development underscores the critical need for robust website security measures and employee training on recognizing phishing attempts. Organizations operating in vulnerable regions, like Ukraine, should prioritize the implementation of advanced threat detection and response protocols to safeguard their digital assets. This incident highlights the evolving tactics of cybercriminals and serves as a stark reminder of the risks posed by social engineering and malicious software, emphasizing the importance of cybersecurity vigilance in today's interconnected digital landscape.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html)*