Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Threat Intel

Hacked Ukrainian sites push Psychedelic Stealer

Arctic Wolf found real websites injected with a fake Cloudflare check that tricks visitors into running a Windows Installer command.

By · Published · Updated · 4 min read

Hacked Ukrainian sites push Psychedelic Stealer

Attackers have compromised legitimate Ukrainian websites to spread a new infostealer called Psychedelic Stealer, Meterpreter.org reports, citing research from Arctic Wolf Labs.

Which sites were hacked

The malicious code was found on real websites belonging to a medical clinic, car and tool retailers, a modelling agency and a publishing house. Attackers injected an iframe that loads a page they control.

How the trick works

  1. Visitors see a fake Cloudflare verification prompt.
  2. Clicking it quietly copies a malicious msiexec (Windows Installer) command to the clipboard.
  3. The page tells the victim to press Win+R, paste and press Enter.
  4. The command installs the stealer.

This is a variant of the ClickFix technique, using Windows Installer instead of the more common PowerShell, which may help it avoid detection.

Why it matters

Visitors trust these sites because they are real businesses. The attack only works if the victim runs the command themselves — which is why it slips past browser protections.

How to stay safe

  • No genuine verification check will ever ask you to open the Run box or paste a command.
  • Website owners should keep their content management systems and plug-ins updated and check for unexpected iframes.

Sources

Read next