---
title: "Fake Cloudflare Verification: How Russian Hackers Target Ukrainian Businesses"
description: "Russian hackers are targeting Ukrainian businesses using fake Cloudflare verification windows, infecting computers with Psychedelic Stealer and RemotePanel."
date: 2026-09-25T14:38:00.000Z
lang: en
url: https://xab.info/en/posts/fake-cloudflare-verification-attacks-ukrainian-business
tags: [cyberattacks, cloudflare, phishing, ukraine, malware]
publisher: "XAB.info"
---

# Fake Cloudflare Verification: How Russian Hackers Target Ukrainian Businesses

![Fake Cloudflare verification window during cyberattack on Ukrainian business](https://xab.info/media/2026/09/25/feykovaya-proverka-cloudflare-ataki-na-ukrainskiy-biznes/feykovaya-proverka-cloudflare-ataki-na-ukrainskiy-biznes-1.webp)

## 🎯 Key Points

- Hackers use fake Cloudflare verification windows in Ukrainian.
- A malicious script copies a command to the clipboard to run via the Run menu.
- About 71% of attack victims are located in Ukraine.
- Psychedelic Stealer malware steals browser passwords, tokens, and crypto wallets.

Russian hackers have launched a new large-scale phishing campaign targeting Ukrainian businesses, including websites of medical clinics, online stores, and other commercial organizations. The attackers use sophisticated disguise under system security notifications to bypass user vigilance and gain unauthorized access to corporate data.

### Essence of the Attack and ClickFix Method

To implement this scheme, hackers infect legitimate web resources with a malicious script. When a visitor opens the infected page, a fake Cloudflare security check window appears in Ukrainian to create an appearance of legitimacy. The script automatically copies a dangerous Windows system command msiexec.exe to the clipboard, after which the victim is prompted to press Win+R and paste the copied text.

### Download Simulation and Malware Software

To force the victim to follow instructions, the site simulates a loading process for 35 seconds until the interface unlocks. Executing the command downloads an MSI installer from the uasputnik[.]com domain, deploying the Psychedelic Stealer malware. This software is designed to steal saved passwords, authorization tokens from popular browsers, and cryptocurrency wallets like MetaMask, Trust Wallet, Exodus, and Atomic Wallet.

### Threat Scale and Control Panel Analysis

Arctic Wolf analysts discovered the campaign's control panel named "РУБЛЕВКА TDS". Panel statistics show that out of 557 views of infected pages, 446 occurred in Ukraine, accounting for about 71% of all victims. The focus on Ukrainian users and the Russian-language interface clearly indicate the origin of the cyberattacks.

### Additional Modules and Security Bypass

Researchers from Blackpoint Cyber recorded the parallel use of a similar scheme to deliver other dangerous modules — RemotePanel and BoundSiphon. In this variation, the malware bypasses User Account Control (UAC), configures exclusions in Microsoft Defender, and provides full remote control over the compromised PC while stealing documents.

## 🔍 Fact-Check Verification

- [Фейковая проверка Cloudflare: как российские хакеры атакуют украинский бизнес](https://www.rbc.ua/ukr/news/feykova-perevirka-cloudflare-k-rosiyski-hakeri-1790342544.html) - Данные подтверждены публикациями профильных ИБ-изследователей Arctic Wolf и Blackpoint Cyber.

## ❓ FAQ

### Q: How does the fake Cloudflare verification work?
**A:** The site mimics a security check window, copies a malicious command to the Windows clipboard, and tricks the user into running it via Win+R.

### Q: What data does Psychedelic Stealer steal?
**A:** The program collects saved passwords and tokens from popular browsers and scans for cryptocurrency wallets.

### Q: What percentage of victims were recorded in Ukraine?
**A:** According to the control panel statistics, approximately 71% of infected page views occurred in Ukraine.