ClickFix campaign injects fake Cloudflare lures
🛡️ Arctic Wolf Labs and Blackpoint Cyber reported an active ClickFix campaign compromising Ukrainian business websites to serve bogus Cloudflare verification pages that trick victims into executing an MSI installer. The MSI chain delivers a newly observed information stealer called Psychedelic, which harvests browser credentials, tokens, and crypto-wallet data, sets persistence, and contacts a C2 for follow-on tasks. Researchers also linked the ClickFix chain to other payloads including RemotePanel and BoundSiphon, highlighting modular remote-access and data-theft capabilities and evidence pointing to likely Russian-speaking operators.
