446 views, 351 clicks and 71 completed events in Ukraine — those figures, recorded by a lure-management panel, underscore a campaign that used hacked Ukrainian business sites to trick visitors into running a Windows Installer command and deliver a previously undocumented information stealer named Psychedelic, Arctic Wolf Labs told The Hacker News.
ClickFix lure and fake Cloudflare verification
Arctic Wolf Labs reported that attackers compromised legitimate Ukrainian business websites — including a hair-treatment clinic, a scale-model manufacturer, a specialist bookseller and publisher, a psychological facility, a tool retailer, and an automotive retailer — and injected an iframe that loads attacker-controlled JavaScript from fsputnik[.]com/tds/tracker[.]js. The injected page imitates a Cloudflare verification screen and presents Ukrainian-language instructions. "When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the Windows Run dialog," Arctic Wolf said.
The ClickFix chain uses an msiexec.exe command to fetch a Windows MSI installer (example filename elita.msi) hosted on uasputnik[.]com. Arctic Wolf noted that the clipboard operation occurs before the lure displays Windows Run instructions and that, after a three-second spinner, the page keeps its "Done" button disabled for roughly 35 seconds — a delay that "controls progression through the lure interface," Arctic Wolf said.
Psychedelic Stealer: capabilities, payloads, and infrastructure
The MSI installer retrieved by the ClickFix command downloads a follow-on binary, psychedeliclove.exe, from 107.175.82[.]242:9000. The 64‑bit executable, which Arctic Wolf calls Psychedelic Stealer, is built to harvest browser passwords, account tokens and cryptocurrency-wallet data, to establish scheduled-task persistence, and to contact a command-and-control server for further tasking.
Psychedelic exfiltrates collected data to endpoints such as /api/v1/ext/passwords, /api/v1/ext/tokens, /api/v1/ext/wallets and /api/v1/checkin. It targets Chromium‑based browsers — Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Vivaldi and Yandex — and scans for known wallet browser extensions (MetaMask, Trust Wallet, OKX Wallet and SafePal) as well as desktop wallets (Exodus, Atomic Wallet, Electrum, Bitcoin Core and Litecoin Core).
The implant also modifies browser profiles: it can terminate selected browser processes, extract an embedded extension archive into web browser profiles and set up a native‑messaging bridge. Arctic Wolf observed a "recurring background routine" that revisits extension-related operations before polling the C2, indicating that the browser-component handling is integrated into the implant's ongoing execution rather than limited to initial installation. Psychedelic also supports a tasks API — /api/v1/agent/tasks?hwid=%s — that allows operators to run EXE, COM, BAT, CMD, MSI and PowerShell payloads.
Arctic Wolf cataloged additional MSI payload names seen in the campaign, including miks.msi, astra.msi, harbor.msi, neon.msi, sova.msi and vyse.msi; the uasputnik[.]com domain was registered on September 9, 2026.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleРУБЛЁВКА TDS lure panel and campaign telemetry
Arctic Wolf identified an exposed lure-management dashboard labeled РУБЛЁВКА TDS on uasputnik[.]com. The panel is separate from the implant C2 at 193.178.159[.]128:8080 and is used to configure web-lure commands and record visitor interactions. "The dashboard polls visitor records every two seconds, providing near-real-time visibility into progression through the lure interface, not endpoint execution," Arctic Wolf said.
At the time of analysis the panel recorded 557 views, 426 clicks and 79 complete events across 32 countries. Ukraine accounted for the majority: 446 views, 351 clicks and 71 complete events; other recorded targets included the U.S., Poland, Germany, Canada and the Netherlands. Arctic Wolf concluded that "Russian-language branding and implementation artifacts suggest likely Russian operators, and the intended audience is clear: Ukrainian-language instructions, affected Ukrainian business websites, and the panel's concentration of recorded views in Ukraine support an assessment that the campaign focused heavily on Ukrainian users."
RemotePanel and BoundSiphon: ClickFix delivers additional .NET tooling
Independent analysis by Blackpoint Cyber reported a related ClickFix chain delivering two undocumented .NET components: RemotePanel, a persistent remote-access platform, and BoundSiphon, a .NET credential and cryptocurrency stealer that targets both Chromium and Firefox. Blackpoint said the sequence begins with a ClickFix PowerShell command that abuses the CMSTPLUA COM object to bypass User Account Control (UAC) and run a privileged hidden PowerShell process.
Blackpoint described RemotePanel as masquerading as the Windows Time service to establish persistence and provide operators broad control — interactive PowerShell sessions, file and process management, screen access, modular hidden VNC (hVNC) and fleet management. RemotePanel resolves its C2 through a BNB Smart Chain contract to allow backend rotation without rebuilding the implant, Blackpoint said. BoundSiphon runs primarily from memory and is used for credential and wallet collection; Blackpoint noted overlap between BoundSiphon and a stealer distributed via five malicious NuGet packages in May 2026.
The ClickFix chain also configures Microsoft Defender exclusions before fetching and executing the two payloads: RemotePanel is written to disk and installed as a service, while BoundSiphon is loaded directly into memory.
What this means for technologists, affected enterprises, and end users
- Technologists and security teams should note the multi-stage ClickFix patterns: msiexec-driven MSI retrievals from uasputnik[.]com, follow-on download from 107.175.82[.]242:9000, the C2 address 193.178.159[.]128:8080, and the fsputnik[.]com tracker — telemetry for detection and blocking comes from those exact artifacts.
- Affected enterprises — particularly the Ukrainian businesses whose sites were compromised — will need to investigate injected iframe elements, remove attacker-controlled JavaScript and review any exposed management dashboards such as the РУБЛЁВКА TDS panel that recorded visitor progress.
- End users should be wary of browser-level "verification" webpages that copy commands to the clipboard and instruct pasting into the Windows Run dialog; Arctic Wolf described that precise clipboard-to-Run pattern and the 35-second lure delay as central to the social-engineering trick.
The campaign combines social-engineering lures hosted on hijacked Ukrainian sites, a previously undocumented stealer with persistent browser‑component behavior, and modular .NET implants that enable remote access and memory-resident theft. Together the artifacts — uasputnik[.]com, fsputnik[.]com, the listed MSI names, the download host 107.175.82[.]242:9000 and the C2 at 193.178.159[.]128:8080 — provide concrete signals for defenders to track as analysis continues.
https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html




