Find notable cyber news and cases, enriched with sources, timelines, and signals.

Unattributed Rublevka TDS (РУБЛЁВКА TDS) lure panel campaign expands across multiple victims

Campaign
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

The ClickFix campaign is compromising legitimate Ukrainian business websites with fake Cloudflare verification pages to deliver the Psychedelic information stealer. The operation uses a copied Windows Installer command and msiexec.exe to stage MSI payloads, putting browser credentials, tokens, and wallet data at risk. Its lure panel shows activity across 32 countries, with the heaviest concentration in Ukraine, indicating a coordinated multi-victim operation.

Related Happenings

Psychedelic Stealer MSI-delivered browser-and-wallet theft activity

Malware Activity
H score30 First: 24.09.2026 17:29 Last: 24.09.2026 17:29 Sources 1

How related: The MSI installer, for its part, is responsible for retrieving the next-stage payload ("psychedeliclove.exe") from the URL "107.175.82[.]242:9000." The 64-bit Windows executable is Psychedelic Stealer, which performs the following functions -

About this happening: The Psychedelic Stealer malware activity is using MSI-delivered payloads to steal browser credentials, account tokens, wallet data, and host information from *...

Silver Fox bogus software-download websites campaign

Campaign
H score38 First: 02.09.2026 19:41 Last: 02.09.2026 19:41 Sources 1

About this happening: An active Silver Fox (aka Yinhu) campaign is using bogus software-download websites to impersonate trusted vendors and deliver malicious installers, exposing China-based...

Venom Stealer MaaS continuous credential theft and exfiltration

Malware Activity
H score29 First: 01.04.2026 16:30 Last: 01.04.2026 16:30 Sources 1

About this happening: The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...

Compromised legitimate WordPress websites used to infect visitors with infostealer malware campaign expands across multiple victims

Campaign
H score34 First: 11.03.2026 16:45 Last: 11.03.2026 16:45 Sources 1

About this happening: A global ClickFix campaign is abusing compromised WordPress sites to push infostealer malware to visitors, putting credentials and financial data at risk. The operatio...

ClickFix compromised-site MIMICRAT campaign

Campaign
H score37 First: 20.02.2026 13:55 Last: 20.02.2026 13:55 Sources 1

About this happening: The ClickFix campaign is abusing compromised legitimate sites to deliver the MIMICRAT remote access trojan through a multi-stage infection chain, widening risk acr...

Timeline

  1. 24.09.2026 17:29 1 articles · 2h ago

    Rublevka TDS lure management panel is exposed on uasputnik[.]com

    Technical Analysis Update

    An exposed lure management panel linked to Rublevka TDS appears on uasputnik[.]com, and the domain is registered on September 9, 2026. The panel configures web-lure commands and records visitor interactions.

    Show sources
  2. 24.09.2026 17:29 2 articles · 2h ago

    ClickFix lures on Ukrainian business websites deliver Psychedelic Stealer

    Initial Disclosure

    A ClickFix lure on legitimate Ukrainian business websites injects bogus Cloudflare verification pages, copies a Windows Installer command to the clipboard, and directs visitors to paste it into the Windows Run dialog. The chain uses msiexec.exe to fetch MSI payloads that deliver Psychedelic Stealer, which harvests browser passwords, account tokens, and cryptocurrency-wallet data; the lure panel also recorded 557 views, 426 clicks, and 79 complete events across 32 countries, with Ukraine accounting for most activity.

    Show sources