Psychedelic Stealer MSI-delivered browser-and-wallet theft activity
Malware Activity
Summary
Hide ▲
Show ▼
The Psychedelic Stealer malware activity is using MSI-delivered payloads to steal browser credentials, account tokens, wallet data, and host information from Windows systems. It targets Chromium-based browsers and sets scheduled-task persistence while maintaining contact with a C2 server for additional tasking. The implant also modifies browser profiles with an embedded extension archive and a native-messaging bridge, extending the theft operation beyond a one-time run.
Related Happenings
Unattributed Rublevka TDS (РУБЛЁВКА TDS) lure panel campaign expands across multiple victims
Campaign
H score36
First: 24.09.2026 17:29
Last: 24.09.2026 17:29
Sources 1
How related:
An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic.
About this happening:
The ClickFix campaign is compromising legitimate Ukrainian business websites with fake Cloudflare verification pages to deliver the Psychedelic information stealer...
Unattributed Rublevka TDS (РУБЛЁВКА TDS) lure panel campaign expands across multiple victims
CampaignHow related: An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic.
About this happening: The ClickFix campaign is compromising legitimate Ukrainian business websites with fake Cloudflare verification pages to deliver the Psychedelic information stealer...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
H score16
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware ActivityAbout this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
ClickFix AmnesiaStealer distribution campaign targeting mac users
Campaign
H score22
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...
ClickFix AmnesiaStealer distribution campaign targeting mac users
CampaignAbout this happening: A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...
Latest development: 16.08.2026 18:07
Jamf described AmnesiaStealer's stream_module and remote_stream commands, which copy a victim's Chromium profile into a hidden headless browser and open WebSocket and Chrome DevTools Protocol channels through webSocketDebuggerUrl. The operator can issue navigation and mouse commands, receive live screencasts, and export or import cookies to operate online portals inside the victim's authenticated sessions on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware Activity
H score29
First: 21.07.2026 12:30
Last: 21.07.2026 12:30
Sources 1
About this happening:
The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware ActivityAbout this happening: The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
Famous Chollima ClickFake Interview recruitment scam campaign
Campaign
H score34
First: 21.07.2026 12:30
Last: 21.07.2026 12:30
Sources 1
About this happening:
A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote a...
Famous Chollima ClickFake Interview recruitment scam campaign
CampaignAbout this happening: A Famous Chollima recruitment scam is targeting Web3 and cryptocurrency professionals with fake job interviews and malicious assessment portals that deliver remote a...
Timeline
-
24.09.2026 17:29 2 articles · 2h ago
Fake Cloudflare ClickFix lures deliver Psychedelic Stealer on Ukrainian business websites
Initial DisclosureLegitimate Ukrainian business websites were compromised to inject bogus Cloudflare verification pages that copied a Windows Installer command to the clipboard and steered visitors into the Windows Run dialog, allowing the ClickFix chain to fetch elita.msi from uasputnik[.]com with msiexec.exe and deliver Psychedelic Stealer. The implant retrieves psychedeliclove.exe from 107.175.82[.]242:9000, steals browser passwords, account tokens, and cryptocurrency-wallet data from Chromium-based browsers and wallet software, collects host information, sets scheduled-task persistence, modifies browser profiles, and uses native messaging plus C2 task polling for follow-on execution.
Show sources
- Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer — thehackernews.com — 24.09.2026 17:29
- Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer — thehackernews.com — 24.09.2026 17:29