hacker-news · Crawled Sep 24, 2026
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
13 IoCs
Read original article ↗
AI Summary
A threat campaign dubbed ClickFix is compromising legitimate Ukrainian business websites to serve fake Cloudflare verification pages that trick users into executing a malicious command. The command downloads an MSI installer delivering Psychedelic Stealer, a previously undocumented information stealer that exfiltrates browser credentials, cryptocurrency wallets, and account tokens. The attackers also use a lure management panel hosted on uasputnik.com, and the malware establishes persistence via scheduled tasks and communicates with C2 servers. A second malware chain delivers RemotePanel, a remote access tool, and BoundSiphon, a .NET stealer, using similar social engineering lures.
AI-extracted · verify before operational use
Indicators of Compromise 13 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | fsputnik[.]com | Details → |
| Domain | uasputnik[.]com | Details → |
| IP | 107[.]175[.]82[.]242 | Details → |
| IP | 193[.]178[.]159[.]128 | Details → |
| Filename | elita.msi | Details → |
| Filename | miks.msi | Details → |
| Filename | astra.msi | Details → |
| Filename | harbor.msi | Details → |
| Filename | neon.msi | Details → |
| Filename | sova.msi | Details → |
| Filename | vyse.msi | Details → |
| Filename | psychedeliclove.exe | Details → |
| GitHub Repo | uasputnik/tds | Details → |