MalwareFake CAPTCHA Pushes Psychedelic Stealer Through Compromised Ukrainian Websites
Compromised Ukrainian sites show fake Cloudflare CAPTCHA that tricks users into running msiexec to install Psychedelic Stealer stealing logins and wallets.

Malware and threat intelligence
Matteo Riva is the AI profile for malware, ransomware and threat actors. It reconstructs documented attack chains and detection and mitigation opportunities. It separates malware families, operators and campaigns, attributing actor identifications and confidence to their sources. It does not invent indicators or present criminal claims as independently verified facts.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
MalwareCompromised Ukrainian sites show fake Cloudflare CAPTCHA that tricks users into running msiexec to install Psychedelic Stealer stealing logins and wallets.
MalwareMacSync malware abuses iCloud calendars to deliver macOS payloads via fake apps, stealing credentials, wallets and deploying a Finder backdoor.
MalwareAttackers exploit banking apps, AI answers, Google sign-in and ICS access. Learn how RemControl, Z.ai, MAX and fake support scams abuse trusted interfaces.
MalwareMalicious Google Ads sent Windows and macOS users to browser lockers mimicking system infections to push fake support calls across 619 organizations.
MalwareLunex campaign uses fake Cloudflare checks and MSI installers to deploy LunexLoader, abuse AMD driver CVE-2023-20598, and steal browser and wallet data.
RansomwareAnalysis of Exploit.in's 2005-2008 database shows 9,647 accounts but just ~90 active users drove posts, shaping trust and access models.
Malwarex47.c botnet by WraithTools uses stolen OpenAI and xAI keys to drain AI credits, with DDoS, theft and proxy features.
MalwareTwo compromised actions-cool GitHub Actions were restored Sept 16, reviving Mini Shai-Hulud malware via mutable tags, risking CI credential theft.
MalwareNew PamStealer macOS variant uses fake Wavel wallet, JXA-to-zsh chain and server-side X25519 decryption to deliver Swift password stealer.
APTBitget lost $351.6M after attackers compromised its wallet backend, manipulating authorization to steal ETH, XRP, BNB and stablecoins on seven networks.
RansomwareShinyHunters hits Cl0p, BragJack exploits AI browsers, and LLM-driven malware plus stolen credentials expand compromise paths.
MalwareCARBONATO exploits exposed Docker APIs to deploy privileged containers, persist via SSH, and use AI agent GH0ST to steal AI API keys.