Securityaffairs Psychedelic Stealer Campaign Targets Ukrainian Websites with Fake CAPTCHA
Article Content
- •Psychedelic Stealer is distributed via compromised Ukrainian websites using a fake CAPTCHA.
- •The malware targets browser credentials and cryptocurrency data, employing a stealthy installation method.
- •The campaign has impacted users across 32 countries, primarily in Ukraine.
A new malware campaign named Psychedelic Stealer is exploiting compromised Ukrainian business websites to deliver a fake Cloudflare CAPTCHA. This lure, presented through injected iframes, directs users to execute a Windows Installer command that downloads the malware. The campaign has affected visitors from 32 countries, with a significant number of interactions recorded from Ukraine. The malware targets sensitive data, including browser passwords and cryptocurrency wallet information, and establishes persistence through scheduled tasks. The attack method bypasses traditional security measures by avoiding PowerShell and using msiexec instead. The lure management panel revealed extensive telemetry data, but it does not confirm successful malware execution. The campaign leverages trusted websites, making it harder for users to identify the threat. As of now, the attack continues, with ongoing monitoring by Arctic Wolf Labs.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Psychedelic Stealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
New ChainScript RAT Exploits ClickFix Lures with Blockchain C2 A newly discovered Node.js remote access trojan (RAT) named ChainScript is being deployed through ClickFix social engineering tactics, targeting Windows systems. The malware utilizes a unique command-and-control (C2) discovery method by querying a Polygon blockchain smart contract to dynamically rotate its server…
HBO Max Account Compromise Fuels ClickFix Malware Campaign In September 2026, hackers compromised the verified HBO Max Reddit account, launching a ClickFix campaign that distributed 108 malicious ads over 48 hours. The ads targeted both macOS and Windows users, tricking them into executing commands that installed information-stealing malware. This operation, dubbed…