The record
Written by software from the 1 report below. The points restate them; where one says why it matters, that is Prism's reading, not a reported fact.
- Threat actors are injecting malicious iframes into legitimate Ukrainian websites to trigger a fake Cloudflare verification screen.
- Users are tricked into copying a Windows command that downloads and executes the Psychedelic information stealer.
- The malware harvests credentials, cryptocurrency wallets, and browser session tokens from infected systems.
- This campaign primarily targets Ukrainian users and relies on Russian-language implementation artifacts.
What to watch next
- Potential expansion of the campaign to other regions beyond Ukraine
- Further use of the Rublevka TDS panel by malicious actors
- Evolution of the Psychedelic malware's capability to deliver secondary payloads
Who said what3
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Arctic Wolf
2 quotes · 1 outlet
“When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the Windows Run dialog,”
In the article
…has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. " When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the Windows Run dialog, " Arctic Wolf Labs said in a technical report shared with The Hacker News. The ClickFix chain uses an "msiexec.exe" command to fetch a Windows MSI installer that's used to deliver the stealer malware. The malicious tool…
“The attacker-controlled page imitates a Cloudflare verification screen and presents Ukrainian-language instructions,”
In the article
…("elita.msi") hosted on "uasputnik[.]com," a domain that was registered on September 9, 2026. Other MSI payloads identified include "miks.msi," "astra.msi," "harbor.msi," "neon.msi," "sova.msi," and "vyse.msi." " The attacker-controlled page imitates a Cloudflare verification screen and presents Ukrainian-language instructions, " Arctic Wolf said. "The clipboard operation occurs before the lure displays its Windows Run instructions. After a three-second spinner, the page presents an instruction dialog and keeps the 'Done' button disabled for…
Blackpoint Cyber
1 quote · 1 outlet
“RemotePanel establishes persistence by masquerading as the Windows Time service and gives operators broad control over infected systems, including PowerShell, file and process management, screen access, modular HVNC, and fleet management,”
In the article
…components delivered together via a ClickFix chain: RemotePanel, a persistent remote access platform, and BoundSiphon, a .NET credential and cryptocurrency stealer that targets both Chromium and Firefox browsers. " RemotePanel establishes persistence by masquerading as the Windows Time service and gives operators broad control over infected systems, including PowerShell, file and process management, screen access, modular HVNC, and fleet management, " researchers Nevan Beal, Sam Decker, and Andi Ursry said. "BoundSiphon runs primarily from memory and targets browser credentials and sessions, cryptocurrency wallets, password manager data, and selected documents,…
Coverage1
All filed from India
Named Ukraine · United States · Poland · Germany · Canada · Netherlands · Cloudflare · Arctic Wolf · Blackpoint Cyber · BoundSiphon · Psychedelic · RemotePanel
The 1 report is listed beside the record.
Corrections and versions
A correction says what was wrong and why. Every earlier headline and brief of this record is kept.
Something wrong?
Say what, and it arrives with this record's address filled in. A correction is welcome.
Ask this story
Answers cite the reports above, or say they can't.
