← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 25, 2026 · 13:49via Security Affairs

ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer

Brief

Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals browser and crypto credentials.

Psychedelic Stealer is being distributed through compromised Ukrainian business websites. Attackers injected hidden iframes into legitimate pages and used them to display a fake Cloudflare verification screen to visitors. The affected sites included a hair-treatment clinic, a scale-model manufacturer, a specialist bookseller, a psychological facility, a tool retailer, and an automotive retailer.

These were legitimate businesses with established social media profiles and third-party listings. Visitors were therefore directed to a trusted website they may have visited before, making the fake Cloudflare CAPTCHA harder to recognize.

That’s the core of what makes this campaign uncomfortable to dismiss.

Read more on Security Affairs→