Psychedelic Stealer uses ClickFix lures on compromised legitimate websites to turn fake Cloudflare verification prompts into user-initiated Windows malware execution.
The attack relies on users running a copied msiexec.exe command, which retrieves a malicious MSI that steals credentials, tokens, wallet data, and establishes persistence.
Security teams should determine whether execution occurred, investigate installer and process activity, address persistence and credential exposure, and verify remediation before restoring access.
Hexnode XDR supports process-tree investigation and containment, while Hexnode UEM can support MSI installation restrictions through tested custom scripts.
Psychedelic Stealer is reaching Windows endpoints through compromised Ukrainian business websites displaying fake Cloudflare verification prompts. The campaign uses ClickFix social engineering to persuade visitors to run a Windows Installer command, turning a routine browsing session into a malware installation.
For security administrators, the concern extends beyond suspicious websites. Employees can encounter malicious instructions on legitimate business pages. Defenses must address what happens when a user transfers those instructions from the browser into the operating system.
How the Psychedelic Stealer attack chain works
Attackers injected an iframe into legitimate websites, including retailers and healthcare-related businesses. The injected content references attacker-controlled JavaScript at fsputnik[.]com/tds/tracker[.]js and presents a fake Cloudflare verification flow.
When visitors interact with the lure, it copies an msiexec.exe command to their clipboard. Instructions then direct them to paste it into Windows Run and execute it. The command retrieves a malicious MSI package, which delivers the stealer. Visiting the page alone does not establish infection: the chain depends on user execution.
This distinction should shape triage. Ask whether the employee merely saw the prompt, copied its contents, or actually executed the command. Record the browsing time and affected device, then correlate the report with endpoint evidence.
What Psychedelic Stealer does after execution
The malware collects browser passwords, account tokens, cryptocurrency wallet data, and host information. It also establishes scheduled-task persistence and polls command-and-control infrastructure for further instructions, creating a route for additional payload execution.
Arctic Wolf identified the scheduled task psychedelicloveUtils and payload psychedeliclove.exe. These provide investigation leads alongside the delivery infrastructure. However, token collection does not establish successful account takeover; Arctic Wolf did not observe successful takeover during its investigation.
Featured Resource
Cybersecurity kit
Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.
Build the investigation around execution context. Review installer command lines, download destinations, spawned processes, and activity around the reported browsing session. Correlate these findings with scheduled-task creation, browser-profile changes, and outbound connections.
Treat individual indicators as starting points. An installer process or scheduled task needs context before an analyst can classify it as malicious. Compare suspicious activity with approved software deployment records and expected administrative work.
Use the investigation to answer three operational questions:
Did execution occur? Establish whether the copied command launched and whether a payload reached the endpoint.
What requires containment? Identify active malicious processes, downloaded files, persistence mechanisms, and affected accounts.
What evidence supports recovery? Document remediation and verify that suspicious activity does not recur before restoring normal access.
For prevention, teach employees to report verification pages requesting operating-system commands. Microsoft also recommends application controls and, where unnecessary for business workflows, disabling access to the Run dialog. Pilot restrictions against legitimate support and software installation tasks before deployment.
How Hexnode supports investigation and containment
Hexnode XDR’s Visual Process Tree helps analysts examine parent-child process relationships. Associated event details can provide command-line, file, and network context for investigating suspicious installer activity on affected Windows endpoints.
After identifying malicious activity, administrators can select the appropriate response:
Response objective
Hexnode XDR action
Restrict endpoint connectivity
Isolate Device cuts general network access while maintaining the connection to the Hexnode XDR console.
Stop malicious execution
Kill Process / Kill Process Tree terminates a selected process or its process tree, respectively.
Contain a malicious file
Quarantine File isolates and encrypts the payload on local storage.
These are administrator-initiated containment actions. Use them alongside investigation of persistence and potential credential exposure.
Hexnode UEM can support installer hardening through Execute Custom Script. Hexnode documents a Windows 10 script that disables Windows Installer to prevent MSI installation. This is a broad restriction, so assess its impact on approved deployments and test it before fleet-wide use.
FAQs
How does Psychedelic Stealer infect Windows devices?
Fake Cloudflare verification prompts trick visitors into pasting a malicious command into Windows Run. The command launches Windows Installer to retrieve an MSI package that delivers the malware.
Does visiting a compromised website confirm infection?
No. This attack chain requires the visitor to execute the copied command. Security teams should review endpoint evidence to determine whether installation and malicious activity occurred.
How can Hexnode XDR help contain affected endpoints?
Administrators can use Isolate Device to restrict network access while preserving connectivity to the Hexnode XDR console. Kill Process / Kill Process Tree stops malicious execution, while Quarantine File isolates and encrypts malicious files.
Close the user-driven execution path
The response priority is to connect awareness, execution controls, investigation, and containment. Give employees a clear reporting route, validate installer restrictions, and define who can isolate an endpoint. After an incident, review affected accounts and confirm remediation before returning the device to normal use.
Stop ClickFix Malware at Endpoints
Detect suspicious execution, contain compromised devices, and strengthen Windows threat response with Hexnode UEM and XDR.
Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.