Widespread Cyberattack Targets Ukrainian Websites Using Psychedelic Stealer Linked to Russia
Extensive Cyberattack Hits Ukrainian Online Platforms
According to НВ — Техно: On September 25, a significant cyber assault was detected against multiple Ukrainian websites, traced back to Russian actors. Attackers employed the fraudulent ClickFix technique to distribute the Psychedelic stealer malware, which extracts sensitive data and alters victims' browser profiles.
This breach affected a variety of Ukrainian sites, including healthcare clinics, book publishers, and e-commerce stores. The hackers embedded code featuring a counterfeit Ukrainian-language Cloudflare security confirmation page, prompting victims to manually execute malicious commands via the Windows clipboard. This step triggered the download of an MSI package from a command-and-control domain, resulting in the installation of the 64-bit Psychedelic stealer on infected machines.
Malware Capabilities and Impact
Psychedelic is capable of harvesting passwords from Chrome-based browsers, account tokens, cryptocurrency wallet details such as those from MetaMask and Trust Wallet, along with system information. The malware can also modify browser profiles to maintain communication with its control server and deploy additional harmful modules. Security researchers uncovered an exposed control panel named 'РУБЛЕВКА TDS' containing hundreds of redirects, predominantly originating from Ukraine. Analysis of the attackers’ infrastructure revealed Russian-language code snippets, while operational instructions were tailored specifically for Ukrainian users.
The ClickFix attack method involves the following steps:
- Compromise of a legitimate website;
- Display of a fake Cloudflare security verification page;
- Copying of a command to the Windows clipboard;
- Pasting the command into the system 'Run' dialog;
- Downloading an MSI installer package;
- Installing the Psychedelic stealer malware.
Data stolen includes passwords, account tokens, cryptocurrency wallet details, and system information. This incident on September 25, 2026, highlights the increasing cyber threats faced by Ukrainian digital infrastructure amid ongoing geopolitical tensions.
This cyberattack underscores the persistent targeting of Ukrainian websites by malicious actors. Given the malware’s ability to exfiltrate sensitive information, users must exercise heightened vigilance and maintain robust data security measures. Continuous investigation and proactive defense strategies remain essential to safeguarding Ukraine’s information environment.
Read also

