# The captcha was on their site

2026-09-24

Arctic Wolf says compromised Ukrainian business sites are serving a fake Cloudflare check that copies a Windows Installer command. The panel counted 557 lure views. That is not 557 infections.

Canonical: https://www.fabiocti.com/notes/the-captcha-was-on-their-site/
Author: Fabio Correia

The last captcha notes were a vendor script and a verified Reddit ad. This one is the shop the person already meant to open.

Arctic Wolf Labs, writing today, says attackers injected a frame into legitimate Ukrainian business sites — a clinic, a bookseller, a tool shop, a model maker — and showed a Ukrainian-language Cloudflare check. Clicking it copies a Windows Installer command. The page then tells the visitor to paste that into the Run box. The payload they name Psychedelic Stealer goes after browser passwords, account tokens, and wallet data, and it sets a scheduled task so it is still there tomorrow.

The management panel they found logged 557 views across 32 countries, 446 of them marked Ukraine. Arctic Wolf is explicit that a view, a click, and a “complete” on that panel are not proof the installer ran.

## Why the helpdesk ticket will say “Cloudflare”

The certificate on the business site is still theirs. The person did not follow a lookalike. There is no email to pull. Detections that only watch for a pasted PowerShell blob miss an installer. The Ray ID on the page is decoration. Cloudflare did not issue it.

A small site with a contact form is now a delivery channel for whoever was already a customer. That is a worse trust problem than a random domain, because the victim can truthfully say they only opened the company they buy from.

## What to pull if someone “just confirmed they were human”

The clipboard, not the browser history. Look for an installer that ran in that sitting, then browser passwords, session tokens, and wallet extensions on that profile. Do not treat the panel’s 557 as your victim count, and do not treat a reload of the shop page as clean. The frame can still be in the page they trust.

The domain was real. The check was not.
