[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fquoCY_Qri1SZTRtzZaiMEuQfqLFI2oZr0WSpAWK3ufg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"57baa48b-c2bd-4bc2-9b4e-c658852e183a","fake-cloudflare-pages-on-hacked-ukrainian-sites-spread-psychedelic-stealer","9ffa8b0e-6a4f-409a-8e48-2727f48fd21e","Fake Cloudflare Pages on Hacked Ukrainian Sites Spread Psychedelic Stealer","Attackers compromised legitimate Ukrainian websites by injecting malicious iframes and JavaScript to display convincing fake Cloudflare CAPTCHA verification pages — a ClickFix social engineering technique designed to trick users into voluntarily executing malware. Visitors who followed the prompts inadvertently installed the Psychedelic stealer, which harvests browser credentials, session tokens, and cryptocurrency wallet data. This attack succeeds because users inherently trust recognizable brand interfaces like Cloudflare, lowering their guard against unusual installation requests. The incident highlights the dual risk of website owners failing to secure their CMS platforms and end users lacking awareness of browser-based social engineering tactics. Malware achieving C2 persistence means compromised systems can be leveraged for extended campaigns well beyond the initial infection.","**Immediate actions:**\n- Audit all website files and server configurations for unauthorized iframe injections or JavaScript modifications.\n- Warn users and stakeholders that legitimate Cloudflare or browser verification pages will never ask you to run commands or install software.\n- Force-reset credentials for all website administrators and enable multi-factor authentication on CMS platforms immediately.\n\n**Long-term improvements:**\n- Implement a Content Security Policy (CSP) header on all web properties to block unauthorized iframe and script injection.\n- Enforce regular integrity checks and file-change monitoring on web server directories to detect unauthorized modifications early.\n- Conduct recurring security awareness training focused on ClickFix and social engineering lures that impersonate trusted brands.\n\n**Detection measures:**\n- Deploy endpoint detection and response (EDR) tools configured to alert on suspicious MSI installer executions initiated from browser processes.\n- Monitor outbound network traffic for unexpected C2 communications, particularly to newly registered or low-reputation domains.\n- Implement web application firewall (WAF) rules to detect and block malicious script injection patterns targeting your hosted sites.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 4 – Secure Configuration of Enterprise Assets and Software","CIS Control 14 – Security Awareness and Skills Training","CIS Control 18 – Application Software Security","NIST SP 800-53 SI-3 – Malicious Code Protection","NIST SP 800-53 SC-18 – Mobile Code","NIST SP 800-53 AT-2 – Literacy Training and Awareness","NIST SP 800-53 SI-7 – Software, Firmware, and Information Integrity","OWASP Top 10 A03:2021 – Injection","GDPR Article 32 – Security of Processing (for EU-adjacent data exposure)","NIST CSF DE.CM-1 – Network Monitoring and Detection","published","2026-09-24T21:20:56.71317+00:00","2026-09-24T21:20:56.441+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fhacked-ukrainian-sites-serve-fake.html","hacked-ukrainian-sites-serve-fake-cloudflare-clickfix-lures-for-psychedelic-stea-f6922c","Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":43,"name":44,"slug":45,"description":46,"color":47},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]