Fake Cloudflare pages are telling Windows users to paste malicious commands into Run. Psychedelic targets browser passwords, account tokens and cryptocurrency wallet data.
Published byEdited with GPT-6 SolImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: How are attackers using fake Cloudflare verification pages and ClickFix instructions to target Windows users through compromised Ukrainian b. Article summary: The campaigns exploit a simple trust mistake: a page that looks like a Cloudflare check tells a Windows user to run a command that installs malware. The compromised Ukrainian sites deliver the Psychedelic stealer; the ac. Topic tags: general, general web, documentation. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fak
A convincing verification page can turn a routine website visit into a malware installation—but only if the visitor follows its instructions. In two reported ClickFix cases, fake Cloudflare checks prompt Windows users to run commands themselves. One campaign uses compromised Ukrainian business websites to deliver Psychedelic Stealer; the other uses the widely referenced third-party.com domain. Their shared tactic is not evidence of shared operators or payloads. 31
5
Arctic Wolf Labs reports that attackers placed iframes on legitimate Ukrainian business websites to display a Ukrainian-language fake Cloudflare verification page. When a visitor interacts with the lure, it copies an msiexec command to the clipboard and tells the visitor to paste it into Windows Run. Running that command retrieves an MSI installer used to deliver Psychedelic Stealer. The crucial step is the visitor executing the command; viewing the page alone is not the same as installing the malware. 31
3
Psychedelic targets browser passwords, account tokens and cryptocurrency-wallet data. Reporting on the malware also describes scheduled-task persistence and contact with command-and-control infrastructure for further tasking. Those capabilities make a suspected execution more than a nuisance: defenders should assess both data exposure and whether the malware remains active. 31
3
Arctic Wolf Labs reports victims in 32 countries across Europe, the Americas and Asia-Pacific, despite the Ukrainian-language lure. That is a geographic reach figure, not an infection total; the available reporting does not support a reliable count of infected devices. Arctic Wolf also describes a Russian-branded traffic panel. Branding is a clue about the operation, but it does not, by itself, identify the operators, their location or a particular threat group. 31
The domain third-party.com appears as a placeholder in developer documentation and code examples. BleepingComputer reported that it was serving a counterfeit Cloudflare verification page to Windows visitors and attempting to get them to run a PowerShell command. Other visitors have been shown a harmless decoy. A reference intended as an example can therefore send a reader to a live lure, while the visitor-dependent presentation can make the behavior harder to spot. 5
4
This case should not be folded into the Psychedelic investigation: the reported instruction uses PowerShell rather than the Ukrainian campaign’s msiexec installation chain, and the cited reporting does not establish a common operator or payload. Visiting the domain is not proof that a user executed the command. 5
31
Blackpoint Cyber identified RemotePanel and BoundSiphon delivered together through another ClickFix chain. RemotePanel is a persistent remote-access platform; BoundSiphon targets credentials and cryptocurrency data. Their pairing illustrates why a ClickFix incident cannot be treated solely as a possible one-time password theft: the same social-engineering technique can also open the door to continuing access. Blackpoint’s findings do not establish a connection to Psychedelic or third-party.com. 19
msiexec downloads or PowerShell launches after a browser visit, and determine whether the user ran the clipboard-provided command. Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Fake Cloudflare pages are telling Windows users to paste malicious commands into Run.
Fake Cloudflare pages are telling Windows users to paste malicious commands into Run. Psychedelic targets browser passwords, account tokens and cryptocurrency wallet data.