Russian hackers have launched a new large-scale phishing campaign targeting Ukrainian businesses, including websites of medical clinics, online stores, and other commercial organizations. The attackers use sophisticated disguise under system security notifications to bypass user vigilance and gain unauthorized access to corporate data.
Essence of the Attack and ClickFix Method
To implement this scheme, hackers infect legitimate web resources with a malicious script. When a visitor opens the infected page, a fake Cloudflare security check window appears in Ukrainian to create an appearance of legitimacy. The script automatically copies a dangerous Windows system command msiexec.exe to the clipboard, after which the victim is prompted to press Win+R and paste the copied text.
Download Simulation and Malware Software
To force the victim to follow instructions, the site simulates a loading process for 35 seconds until the interface unlocks. Executing the command downloads an MSI installer from the uasputnik[.]com domain, deploying the Psychedelic Stealer malware. This software is designed to steal saved passwords, authorization tokens from popular browsers, and cryptocurrency wallets like MetaMask, Trust Wallet, Exodus, and Atomic Wallet.
Threat Scale and Control Panel Analysis
Arctic Wolf analysts discovered the campaign's control panel named "РУБЛЕВКА TDS". Panel statistics show that out of 557 views of infected pages, 446 occurred in Ukraine, accounting for about 71% of all victims. The focus on Ukrainian users and the Russian-language interface clearly indicate the origin of the cyberattacks.
Additional Modules and Security Bypass
Researchers from Blackpoint Cyber recorded the parallel use of a similar scheme to deliver other dangerous modules — RemotePanel and BoundSiphon. In this variation, the malware bypasses User Account Control (UAC), configures exclusions in Microsoft Defender, and provides full remote control over the compromised PC while stealing documents.