The Psychedelic Stealer: When the CAPTCHA Is the Installer
Description
Between September 9 and 14, 2026, a Russian-speaking threat actor compromised at least six legitimate Ukrainian small-business websites to deliver a fake Cloudflare verification page. This social engineering campaign, known as the ClickFix chain, tricked victims into manually executing msiexec.exe commands, resulting in 79 infections from 426 clicks. The malware, named Psychedelic, steals browser credentials, session tokens, and cryptocurrency wallet data from multiple wallets including MetaMask and Trust Wallet. It establishes persistence via browser extensions with native-messaging bridges, scheduled tasks, and communicates with a REST API for additional commands. The attack deliberately avoids encoded PowerShell and uses signed Microsoft binaries to evade detection. The targeting is focused on Ukraine with clear financial motives.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Psychedelic Stealer campaign involved compromising legitimate Ukrainian small-business websites to present a fake Cloudflare CAPTCHA page that convinced users to manually run msiexec.exe commands. This led to installation of the Psychedelic malware, which combines credential theft and persistent agent capabilities. It installs browser extensions that use native-messaging bridges, sets scheduled tasks, and polls a REST API for arbitrary executable tasking. The malware targets browser credentials, session tokens, and cryptocurrency wallets such as MetaMask, Trust Wallet, Exodus, Atomic Wallet, and others. The campaign avoids using encoded PowerShell scripts and instead leverages signed Microsoft binaries to bypass common detection mechanisms associated with ClickFix attacks. The infection rate was approximately 14%, with 79 infections from 426 clicks. The operation is financially motivated and focused primarily on Ukrainian victims.
Potential Impact
The Psychedelic Stealer campaign results in theft of sensitive browser credentials, session tokens, and cryptocurrency wallet data, enabling financial theft from victims. The malware establishes persistence on infected systems via browser extensions and scheduled tasks, allowing ongoing control and arbitrary code execution through a REST API. The use of signed Microsoft binaries to bypass detection increases the likelihood of successful infection and evasion of security controls. The targeting of Ukrainian small-business websites and cryptocurrency users indicates a focused financially motivated threat. The infection rate of 14% from clicks demonstrates moderate effectiveness of the social engineering technique.
Defensive Guidance
No official patch or vendor advisory is available for this malware campaign. Mitigation should focus on user education to avoid executing unsolicited msiexec.exe commands, especially those prompted by suspicious CAPTCHA or verification pages. Network defenders should monitor for indicators of compromise such as the listed domains (uasputnik.com, fsputnik.com), IP addresses, URLs, and file hashes associated with Psychedelic. Blocking access to these domains and URLs and scanning for the identified hashes can help reduce infection risk. Because the malware uses signed Microsoft binaries for execution, traditional signature-based detection may be less effective, so behavioral and heuristic detection methods should be employed. Users should verify website authenticity before interacting with CAPTCHA or verification prompts and avoid manual execution of commands from untrusted sources.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://connect.securonix.com/threat-research-intelligence-62/the-psychedelic-stealer-when-the-captcha-is-the-installer-582"]
- Pulse Id
- 6abfb63a870eec5021127b09
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainuasputnik.com | — | |
domainfsputnik.com | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip193.178.159.128 | — | |
ip176.53.159.40 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash06f434695f93d7fd11eeff71358ff69fed79d310a66d993bbcc4ff979c117c90 | — | |
hash38e90affe37342ee36917cdc535fe9bf04589afa8430eb8d1ba1016adcfc1878 | — | |
hash1f250eb486571d99bc1e4d760e37a554 | — | |
hashae5450f32bcb533c5b592c77a7861553 | — | |
hash85e01bdb2aee0217932e108535691c898b138a80 | — | |
hash94a102fb67c4d65a83c64e9d57a79fae7ad63d92 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://uasputnik.com/elita.msi | — | |
urlhttp://107.175.82.242:9000/wilow/psychedeliclove.exe | — | |
urlhttps://fsputnik.com/tds/tracker.js | — |
Threat ID: 6ac367e42cdf04f656e40b23
Added to database: 10/05/2026, 09:03:32 UTC
Last enriched: 10/05/2026, 09:34:08 UTC
Last updated: 10/05/2026, 18:48:08 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.