UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
UAC-0145 leverages ClickFix CAPTCHAs to distribute data-stealing malware to Ukrainian targets.
Summary
Russian state-sponsored threat actor UAC-0145, a sub-cluster of Sandworm (GRU-affiliated), has been observed using fake CAPTCHA checks on compromised websites to trick Ukrainian targets into executing malicious PowerShell commands. The campaign, active from June–July 2026, deployed multiple malware families including GHETTOVIBE, SCOUTCURL, FLUIDLEECH, LOADLOOP, FREAKYPOLL, and Android backdoor COWARDDUCK, leveraging a custom tool called SMARTAXE and Ethereum smart contracts for command delivery obfuscation.
Full text
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware Ravie LakshmananJul 19, 2026Malware / Cyber Warfare Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's primary foreign military intelligence agency. In these attacks, threat actors have been found to leverage fake CAPTCHA checks on compromised websites that instruct prospective targets to execute a PowerShell command in the terminal. "The mentioned command, as an example, could be intended for downloading and saving a VBS file in the Startup autorun directory; one of the variants of such a program was called GHETTOVIBE," CERT-UA said in an alert. The attacks also involve the use of SCOUTCURL, a PowerShell script that performs basic reconnaissance by harvesting details about the infected machine. Some of the other malicious programs found in the infected endpoints are as follows - FLUIDLEECH and LOADLOOP, which act as loaders, with the former masquerading as software for removing computer viruses. FREAKYPOLL, a Python backdoor At least 10 websites are assessed to have been compromised as part of this campaign between June and July 2026. Besides taking advantage of Cloaking.House, a traffic filtering service that makes it possible to serve different pages to different visitors, the attackers have been found to use a bespoke tool called SMARTAXE to dynamically alter the content of a web page depending on the site visitor and display a CAPTCHA check. The CAPTCHA content to be injected into the web page employs the EtherHiding technique to retrieve the domain name of the remote resource from an Ethereum smart contract using an address specified in the source code. CERT-UA said it also identified the threat actor using other attack techniques to break into devices, including backdooring Android devices by distributing APK files via messaging apps, by disguising them as security tools. The malware embedded in the APK file is a full-featured backdoor codenamed COWARDDUCK that can clandestinely collect the following details - Contacts Files matching certain extensions (".conf," ".json," ".ovpn," ".txt," ".doc," ".docx," ".xls," ".xlsx," ".pptx," ".zip," and ".rar") from the directories: "DCIM," "Documents," "Downloads," "Pictures," and "Alarms" Geolocation in real time In tandem, the malware uses the Dropbox cloud service API to upload files, while retrieving commands or data from an external server or from legitimate sites like steamcommunity[.]com. The use of ClickFix by the Kremlin-backed hacking crew marks a departure from prior campaigns that have made use of trojanized installers for Microsoft Windows or Office containing a built-in backdoor or through bogus antivirus software shared via the Signal messaging app. The disclosure comes as ClickFix continues to be an effective social engineering technique for malware delivery across the cyber threat landscape, with bad actors leveraging it to distribute OXLOADER, Mistic, SCMBANKER, ClickLock Stealer, TELEPUZ, and ACR Stealer. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE Android, Cyber warfare, data theft, Malware, mobile security, Nation-State, Social Engineering, Threat Intelligence, Website Security, Windows ⚡ Top Stories This Week URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code ⭐ Featured Resources What Security Teams Must Defend in the New AI Software Supply Chain Identity Fraud Is Changing Fast. See the Attacks Businesses Face in 2026 What 25 Million Alerts Reveal About the Threats SOCs Ignore How to Find and Control Every Script Running Through Your Marketing Stack Modern SASE Guide: Close the Gaps Traditional Network Security Cannot See
Indicators of Compromise
- malware — GHETTOVIBE
- malware — SCOUTCURL
- malware — FLUIDLEECH
- malware — LOADLOOP
- malware — FREAKYPOLL
- malware — COWARDDUCK
- malware — SMARTAXE
- domain — steamcommunity[.]com