Arctic Wolf is tracking a campaign in which hacked Ukrainian business websites display a fake Cloudflare verification via an injected iframe. Visitors manually paste an msiexec command into the Windows Run window. The chain ends with a previously unidentified infostealer labeled “Psychedelic.”
The attackers did not choose an unknown malicious domain; instead, they targeted websites visitors were already visiting. Arctic Wolf found injected iframes on sites including a hair clinic, a scale model manufacturer, a bookstore and publisher, a hardware store, and an auto repair shop. The script pointed to the attackers’ infrastructure.
The fake authentication page displays Ukrainian instructions, while the HTML contains Russian code comments and declares `lang="ru"`. The Ray ID in the footer is also fake. According to the report, Arctic Wolf calls this “window dressing to fool the site visitor.”
msiexec instead of PowerShell
A notable detail: while most ClickFix variants write an encoded PowerShell command to the clipboard, this campaign uses Windows Installer. The command retrieves elita.msi with the /i and /passive options. Detection that is limited to encoded PowerShell therefore misses this step.
The MSI then loads psychedeliclove.exe, a 64-bit Windows executable. This stealer targets Chromium-based browsers such as Chrome, Edge, Brave, Opera, Vivaldi, and Yandex, and collects passwords, account tokens, and wallet data from MetaMask, Trust Wallet, OKX Wallet, SafePal, Exodus, Electrum, and Bitcoin Core. Persistence is achieved via a scheduled task named psychedelicloveUtils. Additionally, the implant polls a C2 server for new tasks and supports EXE, BAT, MSI, and PowerShell files.
Arctic Wolf also encountered an unprotected control panel branded as РУБЛЁВКА TDS. It recorded 557 views, 426 clicks, and 79 “complete” events across 32 countries. Ukraine accounted for 446 views, followed by the United States (31), Poland (16), and Germany (12). The research team emphasizes that these events do not prove execution or infection.
Arctic Wolf has not yet attributed the activity to a known threat group.
Tip: Fake Claude Code installation pages are spreading an infostealer