How are attackers using fake Cloudflare verification pages and ClickFix instructions to target Windows users through compromised Ukrainian bIllustration; not a screenshot of either reported campaign.
AI プロンプト
Create a landscape editorial hero image for this Studio Global article: How are attackers using fake Cloudflare verification pages and ClickFix instructions to target Windows users through compromised Ukrainian b. Article summary: The campaigns exploit a simple trust mistake: a page that looks like a Cloudflare check tells a Windows user to run a command that installs malware. The compromised Ukrainian sites deliver the Psychedelic stealer; the ac. Topic tags: general, general web, documentation. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fak
Arctic Wolf Labsによると、攻撃者は正規のウクライナ企業サイトにiframeを挿入し、ウクライナ語の偽認証画面を表示させた。訪問者が画面を操作すると、msiexecコマンドがクリップボードにコピーされ、Windowsの「ファイル名を指定して実行」に貼り付けるよう案内される。そのコマンドを実行すると、情報窃取型マルウェア「Psychedelic Stealer」を届けるMSI形式のインストーラーが取得される。ページを表示したことと、コマンドを実行して感染したことは別だ。313
Arctic Wolf Labsは、欧州、南北米、アジア太平洋の32カ国で被害者を確認したとしている。ただし、これは感染端末の総数ではなく、確認された被害者の地理的な広がりを示す数字だ。また、ロシアを想起させる表示のトラフィック管理画面も報告しているが、その表示だけで攻撃者の身元、所在地、特定の集団への帰属は判断できない。31