Work Expertise Process About Notes Contact on LinkedIn

Note

The captcha was on their site

The last captcha notes were a vendor script and a verified Reddit ad. This one is the shop the person already meant to open.

Arctic Wolf Labs, writing today, says attackers injected a frame into legitimate Ukrainian business sites — a clinic, a bookseller, a tool shop, a model maker — and showed a Ukrainian-language Cloudflare check. Clicking it copies a Windows Installer command. The page then tells the visitor to paste that into the Run box. The payload they name Psychedelic Stealer goes after browser passwords, account tokens, and wallet data, and it sets a scheduled task so it is still there tomorrow.

The management panel they found logged 557 views across 32 countries, 446 of them marked Ukraine. Arctic Wolf is explicit that a view, a click, and a “complete” on that panel are not proof the installer ran.

Why the helpdesk ticket will say “Cloudflare”

The certificate on the business site is still theirs. The person did not follow a lookalike. There is no email to pull. Detections that only watch for a pasted PowerShell blob miss an installer. The Ray ID on the page is decoration. Cloudflare did not issue it.

A small site with a contact form is now a delivery channel for whoever was already a customer. That is a worse trust problem than a random domain, because the victim can truthfully say they only opened the company they buy from.

What to pull if someone “just confirmed they were human”

The clipboard, not the browser history. Look for an installer that ran in that sitting, then browser passwords, session tokens, and wallet extensions on that profile. Do not treat the panel’s 557 as your victim count, and do not treat a reload of the shop page as clean. The frame can still be in the page they trust.

The domain was real. The check was not.

Cite: Fabio Correia, “The captcha was on their site”, 2026-09-24. https://www.fabiocti.com/notes/the-captcha-was-on-their-site/. Markdown: https://www.fabiocti.com/notes/the-captcha-was-on-their-site.md

Comments

Public thread on the canonical URL. GitHub login keeps this off a spam hole; replies are copied here on the next build so crawlers and models see them in the HTML.

No public replies yet.

Add a comment
All notes