third party.com 的誘導頁與 Psychedelic 個案不能視為同一攻擊;其他 ClickFix 個案亦顯示,風險可能包括持續遠端存取。
How are attackers using fake Cloudflare verification pages and ClickFix instructions to target Windows users through compromised Ukrainian bIllustration; not a screenshot of either reported campaign.
AI 提示
Create a landscape editorial hero image for this Studio Global article: How are attackers using fake Cloudflare verification pages and ClickFix instructions to target Windows users through compromised Ukrainian b. Article summary: The campaigns exploit a simple trust mistake: a page that looks like a Cloudflare check tells a Windows user to run a command that installs malware. The compromised Ukrainian sites deliver the Psychedelic stealer; the ac. Topic tags: general, general web, documentation. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fak
openai.com
網站突然要求你「驗證是真人」,未必只是例行程序。兩宗已報告的 ClickFix 個案都冒充 Cloudflare 安全檢查,關鍵不是用戶看到了甚麼,而是頁面能否說服用戶親手在 Windows 執行指令。一宗經被入侵的烏克蘭企業網站散播 Psychedelic;另一宗涉及常見於開發文件的 third-party.com。手法相似,不代表兩者由同一批人操作,或會安裝同一種惡意程式。315
雖然誘導頁使用烏克蘭語,Arctic Wolf Labs 報告的受害者遍及歐洲、美洲及亞太區32 個國家。這是涉及國家的數目,不是受感染裝置總數;現有報告不足以得出可靠的感染數字。研究亦提及一個帶有俄羅斯品牌元素的流量管理面板,但單憑這項線索,不能確定操作者是誰、身處何地,或將攻擊歸因於某個特定組織。31
third-party.com:範例網址也可能變成陷阱
third-party.com 常被當作開發文件和程式碼範例中的佔位網址。BleepingComputer 報道,該網域曾向 Windows 訪客顯示假 Cloudflare 驗證頁,試圖誘使他們執行 PowerShell 指令;其他訪客則可能看到看似無害的頁面。換言之,文件中原本只作示例的網址,若指向真實網站,讀者可能會被帶到誘導頁;而不同訪客看到不同內容,也會令問題較難察覺。54