Cyberattacks on Ukrainian websites have taken a new turn, with hackers exploiting vulnerabilities to serve fake Cloudflare clickjacking lures that lead victims into downloading a malicious program called Psychedelic Stealer. This sophisticated phishing tactic has compromised thousands of users worldwide, highlighting the growing threat of cybercrime in the region.
The malware, Psychedelic Stealer, is designed to steal sensitive information from infected devices, including login credentials and cryptocurrency wallets. It’s a prime example of how attackers are using social engineering tactics to bypass traditional security measures. Cloudflare, a popular web application firewall (WAF) provider, has been impersonated in the attack, making it harder for users to distinguish between legitimate and malicious content.
The hacking group behind this campaign appears to be targeting Ukrainian websites that utilize Cloudflare’s services. By exploiting vulnerabilities in these sites, they’re able to inject fake clickjacking scripts that mimic the look and feel of legitimate Cloudflare warnings. When a user clicks on the lure, their device is compromised with Psychedelic Stealer malware. This allows hackers to steal sensitive information and use it for further malicious activities.
The attack’s success can be attributed to the attackers’ ability to manipulate users into bypassing security protocols. By creating convincing fake clickjacking lures, they’re able to evade traditional security measures such as antivirus software and firewalls. The fact that these sites are using Cloudflare’s services only adds to the complexity of the issue, making it harder for users to distinguish between legitimate and malicious content.
The implications of this attack are far-reaching, with thousands of users worldwide potentially compromised. The use of fake clickjacking lures and impersonation tactics highlights the growing threat of social engineering attacks in the region. Cybersecurity experts warn that these types of attacks are becoming increasingly sophisticated, making it essential for organizations to adopt robust security measures to protect against such threats.
As a practical takeaway, users should be aware of the dangers of fake clickjacking lures and the importance of verifying the authenticity of warnings before clicking on them. This can be achieved by checking the URL of the warning and looking for any suspicious elements, such as misspelled words or unfamiliar branding. By staying vigilant and adopting good cybersecurity practices, individuals can reduce their risk of falling victim to these types of attacks.
Source: The Hacker News — 2026-09-24