Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
A ClickFix campaign targeted Ukrainian business websites with fake Cloudflare verification pages to deliver the Psychedelic Stealer, which steals browser credentials, account tokens, cryptocurrency wallets, and host data. Separately, Blackpoint Cyber uncovered the RemotePanel and BoundSiphon .NET malware pair, which combines persistent remote access with credential and wallet theft through a multi-stage PowerShell chain. #PsychedelicStealer #ClickFix #RemotePanel #BoundSiphon #ArcticWolfLabs #BlackpointCyber #RublevkaTDS

Keypoints

  • ClickFix compromised legitimate Ukrainian websites with fake Cloudflare verification pages.
  • The lure copied an msiexec command to install the Psychedelic Stealer payload.
  • Psychedelic Stealer collects browser passwords, tokens, wallets, and host information.
  • The campaign used an exposed Rublevka TDS panel to manage lure activity and track victims.
  • Blackpoint Cyber also found RemotePanel and BoundSiphon, a persistent access tool and data-stealing malware pair.

Read More: https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html