Psychedelic Stealer is a new information-stealing malware documented by Arctic Wolf Labs as part of its ClickFix campaign that targets Ukrainian users. Instead of exploiting browser vulnerabilities, operators infiltrate legitimate business websites, insert fake Cloudflare verification pages, and then convince victims to run malicious installation commands themselves.

The fake verification page directs the user to the infection chain using the Windows Installer. Source: The Hacker News.
Background: ClickFix wears a familiar captcha
ClickFix is a social phishing technique in which the victim is asked to copy and run a command to “fix the error” or complete verification. During this campaign, many Ukrainian websites in the retail, publishing, medical and automotive sectors were injected with JavaScript-loaded iframes controlled by the attackers. The interface is Ukrainian, simulating Cloudflare's test step to create a sense of reliability.
When the user interacts, the dummy page silently gives the command msiexec.exe go to the clipboard and open the Windows Run dialog box and paste the command. This loads the MSI packet from the attacker's infrastructure. Thus, the security barrier is overcome by the accidental cooperation of the victim himself, rather than an automatic exploitation.
Campaign progress and infrastructure traces
According to Arctic Wolf Labs, the MSI package distribution domain was registered on 9/9/2026. Installation templates with multiple names such as elita.msi, miks.msi, astra.msi, harbor.msi, neon.msi, sova.msi and vyse.msi. The installation package continues to download the 64-bit executable file containing the “Psychedelic” tag, from which the team named the malicious code.
An exposed bait panel recorded 557 views, 426 clicks, and 79 completed events in 32 countries. Ukraine accounted for 446 views, 351 clicks, and 71 completed events. These figures only reflect the interaction with the interface, not prove that each machine has been infected with malicious code. The US, Poland, Germany, Canada and the Netherlands also appear in the data.
What did Psychedelic Stealer steal?
The malware collects passwords from Chromium-based browsers such as Chrome, Edge, Brave, Opera, Vivaldi, and Yandex. It also targets account tokens, server information, and crypto wallet data, including MetaMask, Trust Wallet, OKX Wallet, SafePal widgets, and many desktop wallet applications.
The potential for danger does not stop at “one-time theft.” Psychedelic Stealer creates scheduled tasks to maintain presence, edit browser profiles, deploy native messaging bridges, and periodically asks the control server if a new task is available. The operator can ask it to run additional EXE, COM, BAT, CMD, MSI, or PowerShell files, making a loss of information a starting point for deeper intrusion.
Who's behind the campaign?
The campaign has not been attributed to a known threat group. Arctic Wolf suggests that the Russian brand on the dashboard and some implementation traces suggest a Russian-speaking operating environment. However, this is only a technical indication, not enough to identify or sponsor a specific organization.
Ukraine's focus was clearer: Ukrainian-language instructions, a compromised Ukrainian business website, and an overwhelming percentage of traffic from the country. Taking advantage of a real website also increases the social impact, because users may lose trust in familiar online services and victim businesses have to bear the additional costs of troubleshooting.
Technical, legal and economic implications
Stolen passwords, session tokens, and wallet data can lead to account hijacking, financial fraud, and chain attacks on partners. For enterprises with websites with codes inserted, the consequences also include interruption of operation, forensic investigation, notification of data breaches and obligations to protect customers under applicable laws.
The campaign shows that browser-based defense technology is no substitute for behavior control. A CAPTCHA page has no good reason to require the user to open Windows Run, PowerShell or Terminal. Any such instruction should be considered an attack signal.
Recommended defenses
- Do not paste commands from the website into Windows Run, PowerShell, Command Prompt or Terminal.
- Close the page as soon as the captcha requests an out-of-browser action; revisit the service using a known address.
- Enterprises need to monitor changes to web files, strange iframes, and JavaScript loaded from newly registered domains.
- Restrictions on Enforcement
msiexec.exefrom the external URL, and also track the child progress and abnormal connections. - If it is suspected that the command has been run, disconnect the device network, collect evidence, change the password from the clean machine, and revoke the session token.
Lessons from Psychedelic Stealer Profile
The strength of the campaign lies in the combination of a hijacked legitimate website, a familiar interface and seemingly simple instructions. Effective defenses need to simultaneously protect the website, control workstation execution, and train users to recognize unusual requests. With captcha, the easiest rule to remember is: validation takes place in the browser, does not require running system commands.
VNCyberS from Arctic Wolf Labs and The Hacker News















