{"id":1993,"date":"2026-09-25T13:59:28","date_gmt":"2026-09-25T08:29:28","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1993"},"modified":"2026-09-29T12:23:51","modified_gmt":"2026-09-29T06:53:51","slug":"ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/","title":{"rendered":"Ukrainian Business Sites Become ClickFix Launchpads for Psychedelic Stealer"},"content":{"rendered":"<p>Psychedelic Stealer is reaching Windows endpoints through compromised Ukrainian business websites displaying fake Cloudflare verification prompts. The campaign uses ClickFix social engineering to persuade visitors to run a Windows Installer command, turning a routine browsing session into a malware installation.<\/p>\n<p>For security administrators, the concern extends beyond suspicious websites. Employees can encounter malicious instructions on legitimate business pages. Defenses must address what happens when a user transfers those instructions from the browser into the operating system.<\/p>\n<h2>How the Psychedelic Stealer attack chain works<\/h2>\n<p>Attackers injected an iframe into legitimate websites, including retailers and healthcare-related businesses. The injected content references attacker-controlled JavaScript at fsputnik[.]com\/tds\/tracker[.]js and presents a fake Cloudflare verification flow.<\/p>\n<p>When visitors interact with the lure, it copies an msiexec.exe command to their clipboard. Instructions then direct them to paste it into Windows Run and execute it. The command retrieves a malicious MSI package, which delivers the stealer. Visiting the page alone does not establish infection: the chain depends on user execution.<\/p>\n<p>This distinction should shape triage. Ask whether the employee merely saw the prompt, copied its contents, or actually executed the command. Record the browsing time and affected device, then correlate the report with endpoint evidence.<\/p>\n<h3>What Psychedelic Stealer does after execution<\/h3>\n<p>The malware collects browser passwords, account tokens, cryptocurrency wallet data, and host information. It also establishes scheduled-task persistence and polls command-and-control infrastructure for further instructions, creating a route for additional payload execution.<\/p>\n<p>Arctic Wolf identified the scheduled task psychedelicloveUtils and payload psychedeliclove.exe. These provide investigation leads alongside the delivery infrastructure. However, token collection does not establish successful account takeover; Arctic Wolf did not observe successful takeover during its investigation.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-1.webp?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity-kit\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-1.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-1-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-1-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-1-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity-kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            Download the Resource Kit\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>What security teams should investigate<\/h2>\n<p>Build the investigation around execution context. Review installer command lines, download destinations, spawned processes, and activity around the reported browsing session. Correlate these findings with scheduled-task creation, browser-profile changes, and outbound connections.<\/p>\n<p>Treat individual indicators as starting points. An installer process or scheduled task needs context before an analyst can classify it as malicious. Compare suspicious activity with approved software deployment records and expected administrative work.<\/p>\n<p>Use the investigation to answer three operational questions:<\/p>\n<ul>\n<li><strong>Did execution occur?<\/strong> Establish whether the copied command launched and whether a payload reached the endpoint.<\/li>\n<li><strong>What requires containment?<\/strong> Identify active malicious processes, downloaded files, persistence mechanisms, and affected accounts.<\/li>\n<li><strong>What evidence supports recovery?<\/strong> Document remediation and verify that suspicious activity does not recur before restoring normal access.<\/li>\n<\/ul>\n<p>For prevention, teach employees to report verification pages requesting operating-system commands. Microsoft also recommends application controls and, where unnecessary for business workflows, disabling access to the Run dialog. Pilot restrictions against legitimate support and software installation tasks before deployment.<\/p>\n<h2>How Hexnode supports investigation and containment<\/h2>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a>\u2019s Visual Process Tree helps analysts examine parent-child process relationships. Associated event details can provide command-line, file, and network context for investigating suspicious installer activity on affected Windows endpoints.<\/p>\n<p>After identifying malicious activity, administrators can select the appropriate response:<\/p>\n<table>\n<thead>\n<tr>\n<th>Response objective<\/th>\n<th>Hexnode XDR action<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Restrict endpoint connectivity<\/td>\n<td><strong>Isolate Device<\/strong> cuts general network access while maintaining the connection to the Hexnode XDR console.<\/td>\n<\/tr>\n<tr>\n<td>Stop malicious execution<\/td>\n<td><strong>Kill Process \/ Kill Process Tree<\/strong> terminates a selected process or its process tree, respectively.<\/td>\n<\/tr>\n<tr>\n<td>Contain a malicious file<\/td>\n<td><strong>Quarantine File<\/strong> isolates and encrypts the payload on local storage.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>These are administrator-initiated containment actions. Use them alongside investigation of persistence and potential credential exposure.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> can support installer hardening through <a href=\"https:\/\/www.hexnode.com\/blogs\/executing-custom-windows-scripts-via-mdm\/\">Execute Custom Script<\/a>. Hexnode documents a Windows 10 script that disables Windows Installer to prevent MSI installation. This is a broad restriction, so assess its impact on approved deployments and test it before fleet-wide use.<\/p>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How does Psychedelic Stealer infect Windows devices?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Fake Cloudflare verification prompts trick visitors into pasting a malicious command into Windows Run. The command launches Windows Installer to retrieve an MSI package that delivers the malware.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does visiting a compromised website confirm infection?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. This attack chain requires the visitor to execute the copied command. Security teams should review endpoint evidence to determine whether installation and malicious activity occurred.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How can Hexnode XDR help contain affected endpoints?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Administrators can use Isolate Device to restrict network access while preserving connectivity to the Hexnode XDR console. Kill Process \/ Kill Process Tree stops malicious execution, while Quarantine File isolates and encrypts malicious files.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Close the user-driven execution path<\/h3>\n<p>The response priority is to connect awareness, execution controls, investigation, and containment. Give employees a clear reporting route, validate installer restrictions, and define who can isolate an endpoint. After an incident, review affected accounts and confirm remediation before returning the device to normal use.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stop ClickFix Malware at Endpoints<\/h5><p>Detect suspicious execution, contain compromised devices, and strengthen Windows threat response with Hexnode UEM and XDR.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Psychedelic Stealer is reaching Windows endpoints through compromised Ukrainian business websites displaying fake Cloudflare verification&#8230;<\/p>\n","protected":false},"author":6,"featured_media":1997,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,16],"class_list":["post-1993","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-windows","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Psychedelic Stealer: Fake Cloudflare ClickFix Attack<\/title>\n<meta name=\"description\" content=\"Psychedelic Stealer spreads through fake Cloudflare prompts on hacked websites. Learn how the attack works and how to protect enterprise endpoints.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Psychedelic Stealer: Fake Cloudflare ClickFix Attack\" \/>\n<meta property=\"og:description\" content=\"Psychedelic Stealer spreads through fake Cloudflare prompts on hacked websites. Learn how the attack works and how to protect enterprise endpoints.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-25T08:29:28+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-29T06:53:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Ukrainian-Business-Sites-Become-ClickFix-Launchpads-for-Psychedelic-Stealer.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"Ukrainian Business Sites Become ClickFix Launchpads for Psychedelic Stealer\",\"datePublished\":\"2026-09-25T08:29:28+00:00\",\"dateModified\":\"2026-09-29T06:53:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\\\/\"},\"wordCount\":813,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Ukrainian-Business-Sites-Become-ClickFix-Launchpads-for-Psychedelic-Stealer.png?format=webp\",\"articleSection\":[\"Malware\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\\\/\",\"name\":\"Psychedelic Stealer: Fake Cloudflare ClickFix Attack\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Ukrainian-Business-Sites-Become-ClickFix-Launchpads-for-Psychedelic-Stealer.png?format=webp\",\"datePublished\":\"2026-09-25T08:29:28+00:00\",\"dateModified\":\"2026-09-29T06:53:51+00:00\",\"description\":\"Psychedelic Stealer spreads through fake Cloudflare prompts on hacked websites. Learn how the attack works and how to protect enterprise endpoints.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Ukrainian-Business-Sites-Become-ClickFix-Launchpads-for-Psychedelic-Stealer.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Ukrainian-Business-Sites-Become-ClickFix-Launchpads-for-Psychedelic-Stealer.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"Ukrainian Business Sites Become ClickFix Launchpads for Psychedelic Stealer\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Ukrainian Business Sites Become ClickFix Launchpads for Psychedelic Stealer\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"description\":\"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Psychedelic Stealer: Fake Cloudflare ClickFix Attack","description":"Psychedelic Stealer spreads through fake Cloudflare prompts on hacked websites. Learn how the attack works and how to protect enterprise endpoints.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/","og_locale":"en_US","og_type":"article","og_title":"Psychedelic Stealer: Fake Cloudflare ClickFix Attack","og_description":"Psychedelic Stealer spreads through fake Cloudflare prompts on hacked websites. Learn how the attack works and how to protect enterprise endpoints.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-25T08:29:28+00:00","article_modified_time":"2026-09-29T06:53:51+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Ukrainian-Business-Sites-Become-ClickFix-Launchpads-for-Psychedelic-Stealer.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"Ukrainian Business Sites Become ClickFix Launchpads for Psychedelic Stealer","datePublished":"2026-09-25T08:29:28+00:00","dateModified":"2026-09-29T06:53:51+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/"},"wordCount":813,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Ukrainian-Business-Sites-Become-ClickFix-Launchpads-for-Psychedelic-Stealer.png?format=webp","articleSection":["Malware","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/","url":"https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/","name":"Psychedelic Stealer: Fake Cloudflare ClickFix Attack","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Ukrainian-Business-Sites-Become-ClickFix-Launchpads-for-Psychedelic-Stealer.png?format=webp","datePublished":"2026-09-25T08:29:28+00:00","dateModified":"2026-09-29T06:53:51+00:00","description":"Psychedelic Stealer spreads through fake Cloudflare prompts on hacked websites. Learn how the attack works and how to protect enterprise endpoints.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Ukrainian-Business-Sites-Become-ClickFix-Launchpads-for-Psychedelic-Stealer.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Ukrainian-Business-Sites-Become-ClickFix-Launchpads-for-Psychedelic-Stealer.png?format=webp","width":1340,"height":700,"caption":"Ukrainian Business Sites Become ClickFix Launchpads for Psychedelic Stealer"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/ukrainian-business-sites-become-clickfix-launchpads-for-psychedelic-stealer\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Ukrainian Business Sites Become ClickFix Launchpads for Psychedelic Stealer"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"description":"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1993","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1993"}],"version-history":[{"count":5,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1993\/revisions"}],"predecessor-version":[{"id":2026,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1993\/revisions\/2026"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1997"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1993"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1993"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}