A cybersecurity firm called Arctic Wolf reported on September 24, 2026, about a widespread cyberattack targeting several legitimate Ukrainian websites. These included a hair clinic, an automobile dealership, a bookstore, a psychiatry office, and a hardware store. The attack appears to have been carried out by a single group or using a shared network of tools, and the websites were chosen without clear patterns. The hackers exploited a technique known as ClickFix, which has been used in previous attacks and continues to be a threat.
The attack involved taking control of real, active websites and turning them into relays for malicious activity. Visitors to these sites would see a fake Cloudflare verification message in Ukrainian, which appeared to be part of the website’s security. This message was hosted on a domain registered on September 9, 2026. When users clicked the verification box, a command was automatically copied to their clipboard. A pop-up then instructed them to "confirm their identity" by pressing the Windows key and the "R" key, pasting the copied text, and pressing enter. This action triggered the execution of a malicious command on the user’s computer.
The command used the Windows Installer, a program that manages software installation, to download a file named elita.msi. This file then retrieved a type of spyware called Psychedelic Stealer, named by Arctic Wolf. The spyware targets browsers based on the Chromium engine, such as Google Chrome, Microsoft Edge, and Brave, and collects saved passwords and account tokens. It also scans for cryptocurrency wallets, including extensions like MetaMask and applications like Exodus. The malware can restart itself every time a user logs in, allowing it to continually communicate with its server and receive new tasks from attackers.
Researchers were able to access what appears to be the attackers’ control panel, which showed that 79 instances of the ClickFix technique had been successfully triggered. However, this does not confirm that users actually executed the malicious commands. The code used in the attack contains Russian comments, but Arctic Wolf has not linked the operation to any known hacker group. The nature of the stolen data—such as login credentials and cryptocurrency information—suggests that the attackers are likely motivated by financial gain.
Cybercriminal Campaign Targets Ukrainian Websites Using ClickFix Technique
AI-rewritten from original reportingHow it works
cybersecurityclickfixpsychedelic-stealerukrainemalwareiframe
Original sources:
- 🇫🇷Numerama



