Attackers have compromised legitimate Ukrainian business websites and injected code that displays fake Cloudflare verification pages in Ukrainian. When visitors interact with the page, the site silently copies a Windows Installer command to their clipboard and instructs them to paste it into Windows Run. This installs Psychedelic Stealer, which harvests browser passwords, account tokens, and data from crypto wallets including MetaMask, Trust Wallet, Exodus, and others. A management panel called “ะ ะฃะะะะะะ TDS” (Rublevka TDS) tracked 557 views and 79 completed infections at the time of analysis, with 80% of activity concentrated in Ukraine. Russian operators are the likely source.
This is an active campaign, first documented by Arctic Wolf Labs on September 24, 2026. It targets Ukrainian internet users through compromised local business websites, using a social engineering technique called ClickFix that has become one of the most effective malware delivery methods in the past 18 months.
Why Compromised Trusted Websites Are More Dangerous Than Phishing Emails
Most people have absorbed the message: don’t click suspicious links in emails. This campaign exploits the gap between that advice and how browsers actually behave.
When you navigate directly to a website you’ve visited before, a local Ukrainian bookshop or an automotive parts retailer, your browser isn’t suspicious. You’re not clicking an email link. You’ve typed the address yourself. Your security software sees a legitimate site loading a legitimate page.
What you don’t see is an injected iframe element quietly loading attacker-controlled JavaScript from the domain “fsputnik[.]com/tds/tracker[.]js”. That script is what builds the fake Cloudflare verification page over the real content. The site has been compromised. The page you see is not the page the site owner built.
This is the same structural vulnerability we’ve covered in looking at how supply chain attacks use trusted third parties as entry points; the attack reaches you through something you already trust.
The ClickFix Chain: Step by Step
The technique is designed around one insight: users will follow instructions from a page that looks authoritative, especially when the visual design matches a platform they recognize.
The fake Cloudflare page is presented in Ukrainian, correctly localized for the target audience. Before showing any instructions at all, it silently copies a Windows msiexec command to the clipboard. The user never knows the copy happened.
After a three-second loading animation, a dialog appears explaining what to do: press Win+R to open the Windows Run box, paste what’s in the clipboard, and press Enter. The “Done” button is deliberately disabled for a further 35 seconds, a delay the researchers note is not a technical verification step but a psychological one, forcing the user to wait and creating the impression that something is being checked.
The msiexec command reaches out to “uasputnik[.]com”, a domain registered on September 9, 2026 โ and downloads an MSI installer. Arctic Wolf identified multiple payload filenames: elita.msi, miks.msi, astra.msi, harbor.msi, neon.msi, sova.msi, and vyse.msi. The installer then retrieves the actual malware executable, “psychedeliclove.exe,” from a separate IP address.
The “uasputnik” domain name, combining “ua” (Ukraine’s country code) with “sputnik” (the Russian state news agency), reflects the campaign’s apparent Russian origin.
What Psychedelic Stealer Takes
Once installed, Psychedelic hits a specific list of targets in sequence.
For browsers, it targets Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Yandex, every major Chromium-based browser. It steals saved passwords and account session tokens through separate API endpoints. Browser credentials have become the primary commodity in underground credential markets; CRIF Cyber Observatory’s H1 2026 data showed that 95.9% of dark web records include email-and-password combinations.
For cryptocurrency, it scans for both browser extensions and desktop applications: MetaMask, Trust Wallet, OKX Wallet, and SafePal on the browser side; Exodus, Atomic Wallet, Electrum, Bitcoin Core, and Litecoin Core as desktop apps. The wallet data is exfiltrated immediately.
Most significantly, Psychedelic establishes a native messaging bridge, a mechanism that allows code injected into your browser profiles to communicate with a local component running on your machine. This turns the infection into an ongoing, two-way channel rather than a one-time data grab. The malware polls its C2 server for additional tasks and can execute EXE, BAT, CMD, MSI, and PowerShell payloads on demand. What starts as a credential stealer becomes an adaptable remote foothold.
The Russian Management Panel With an Elite Moscow Name
Arctic Wolf Labs discovered an exposed lure management panel tied to the campaign, operating on the same “uasputnik[.]com” domain and named ะ ะฃะะะะะะ TDS, “Rublevka TDS” in English.
Rublyovka is the notoriously wealthy district west of Moscow where Russian oligarchs and senior government officials have historically lived. Naming a criminal malware management panel after it is either an inside joke among the operators or a deliberate flex. Either way, it’s a Russian cultural reference that fits the broader attribution picture.
The panel polls visitor data every two seconds, providing near-real-time tracking of who saw the lure, who clicked, and who completed installation. At the time of analysis: 557 views, 426 clicks, 79 complete infections across 32 countries. Ukraine accounted for 446 views, 351 clicks, and 71 completions, approximately 80% of all activity concentrated in one country.
Other affected countries included the US, Poland, Germany, Canada, and the Netherlands.
A Second ClickFix Campaign: RemotePanel and BoundSiphon
Separately, Blackpoint Cyber documented a different ClickFix chain delivering two additional undocumented malware components: RemotePanel and BoundSiphon.
RemotePanel masquerades as the Windows Time service and gives operators broad, persistent control, PowerShell access, file and process management, screen streaming, and modular HVNC (Hidden Virtual Network Computing, which lets attackers view and control the desktop invisibly). The critical infrastructure detail: RemotePanel uses a BNB Smart Chain contract to resolve its C2 server. This means attackers can change their backend infrastructure without rebuilding or redeploying the malware by updating a blockchain record. Takedowns that target C2 servers don’t work when the C2 address is stored on a blockchain.
BoundSiphon runs entirely from memory, leaving no disk footprint, and targets credentials across both Chromium and Firefox browsers, including data protected by Chrome’s newer App-Bound Encryption (a mechanism Google introduced specifically to block exactly this kind of external credential theft). The attack chain uses the CMSTPLUA COM object to bypass Windows User Account Control (UAC) without triggering any user prompts and then configures broad Microsoft Defender exclusions before deploying.
Both campaigns remain unattributed to named threat actor groups. However, both show artifacts consistent with Russian-speaking operators, including, in the case of BoundSiphon, explicit code checks to skip execution if it detects a Russian keyboard layout.
Why Ukraine Is the Primary Target
The campaign is notable for its clear geographic focus. Ukrainian-language instructions, Ukrainian business websites as the delivery vector, and 80% of registered activity in Ukraine are not coincidences in a conflict where cyberattacks have accompanied military operations since 2022.
Credential theft targeting Ukrainian civilians and businesses serves intelligence purposes beyond financial fraud; accessing email accounts, corporate systems, and communications of people in a country under active military pressure has obvious value for state-adjacent actors. The dark web early warning pattern we’ve covered applies here: credential harvesting campaigns often precede or accompany larger-scale operations.
Ukraine’s national CERT, CERT-UA, actively tracks ClickFix and similar social engineering campaigns and is the appropriate contact for Ukrainian organizations that may have been compromised.
What to Do If You Think You Were Affected
If you’ve recently visited a Ukrainian business website and followed any unexpected browser verification instructions, assume compromise.
Change passwords for all accounts whose credentials are stored in your browser, immediately and completely, not just for sensitive accounts. Revoke active sessions for any services that allow session management (Google, Microsoft, major banking sites).
For cryptocurrency wallets, if seed phrases or wallet files were stored anywhere accessible to your browser, treat those wallets as compromised. Move funds to a new wallet with a fresh seed phrase generated on a clean device.
Enable two-factor authentication using an authenticator app rather than SMS on every account that supports it. Run a full antivirus scan, checking specifically for scheduled tasks the installer may have created.
Our guide on what to do when your data is on the dark web covers a broader credential-exposure checklist for anyone whose accounts may now be in criminal hands.
Frequently Asked Questions
What is ClickFix?
A social engineering technique where a fake browser verification or error page instructs users to paste a command into the Windows Run dialog. The command has already been silently copied to the clipboard. Running it installs malware.
What is Psychedelic Stealer?
A newly documented Windows malware that harvests browser passwords, account tokens, and cryptocurrency wallet data, installs a native messaging bridge in browser profiles for persistent access, and can receive additional payloads from a command-and-control server.
Who is behind this campaign?
Attribution remains unconfirmed, but Russian-language branding (including the “Rublevka TDS” panel name) and the targeting of Ukrainian users and businesses are consistent with Russian-speaking threat actors.
Which crypto wallets are at risk?
MetaMask, Trust Wallet, OKX Wallet, and SafePal as browser extensions; Exodus, Atomic Wallet, Electrum, Bitcoin Core, and Litecoin Core as desktop applications.