Arctic Wolf Labs reported an active ClickFix campaign that compromised legitimate Ukrainian business websites, including a hair-treatment clinic, a scale-model manufacturer, and a bookseller. The injected iframe executed attacker-controlled JavaScript that displayed a fake Cloudflare verification screen with Ukrainian-language instructions. When a visitor interacted, the lure copied a Windows Installer command to the clipboard and told them to paste it into the Windows Run dialog.

The command used msiexec.exe to fetch an MSI installer from uasputnik[.]com, which then retrieved the Psychedelic Stealer executable. The malware collects credentials from Chromium-based browsers, steals account tokens, and scans for cryptocurrency wallet extensions and desktop apps. It also sets scheduled-task persistence, modifies browser profiles, and polls a command-and-control server for tasks, allowing it to run EXE, COM, BAT, CMD, MSI, and PowerShell payloads.

Arctic Wolf said the exposed lure management panel, called Rublevka TDS, recorded 557 views and 79 complete events, mostly from Ukraine. The researchers assessed that Russian-language branding and the focus on Ukrainian sites and users suggest likely Russian operators. Separately, Blackpoint Cyber described another ClickFix chain delivering RemotePanel and BoundSiphon, a persistent remote-access platform and a credential/cryptocurrency stealer.