Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

Ukraine’s Cybersecurity Crisis Deepens as Hacked Sites Distribute Malicious Cloudflare Lures

A new wave of cyberattacks has hit Ukraine, with hacked websites serving up fake security updates that trick users into installing malware. The malicious campaign, which exploits a well-known vulnerability in the cloud-based security platform Cloudflare, has already compromised several high-profile Ukrainian sites. What’s more, these attacks are not just about spreading malware – they’re being used to deliver a sophisticated information stealer designed to plunder sensitive data from unsuspecting victims.

The hackers behind this operation have targeted websites that use Cloudflare, a popular service that helps protect against common web attacks by filtering traffic and blocking malicious requests. However, the attackers have discovered a way to bypass these defenses by exploiting a previously known vulnerability in Cloudflare’s code. They’ve then used this backdoor to inject fake security updates onto compromised sites, warning users of “critical” vulnerabilities that only they can fix – for a hefty price.

These fake security updates are designed to look and feel like legitimate patches from Cloudflare, complete with convincing warnings and system checks. However, what’s actually happening is the installation of a sophisticated information stealer called Psychedelic Stealer. This malware siphons off sensitive data, including login credentials, credit card numbers, and other personal details, which are then sent back to the attackers for further use.

The affected Ukrainian sites include several high-profile government and business websites, which have been compromised through a combination of social engineering and technical exploitation. The hackers likely gained access to these sites by exploiting weak passwords or using advanced phishing techniques to trick employees into divulging sensitive information. Once inside, they used their Cloudflare vulnerability exploit to inject the malicious code.

The implications of this attack are serious. Not only have several Ukrainian websites been compromised, but the Psychedelic Stealer malware poses a significant threat to anyone who visits these sites or clicks on the fake security updates. This is especially concerning given the sensitive nature of the data being targeted – if you’re an organization that handles financial information or personal data, your systems are now at risk.

So what can you do to protect yourself? The first step is to be aware of this threat and take a closer look at any security updates that your website or software providers suggest. Be wary of unsolicited patches or alerts – if they seem too good (or bad) to be true, they probably are. Regularly patching your systems, using strong passwords, and implementing robust security measures will also help reduce the risk of such attacks. Most importantly, stay informed about emerging threats like this one, so you can take action before it’s too late.


Source: The Hacker News — 2026-09-24