Back to all lessons
Awareness Lessons
3 months ago

Fake CAPTCHAs Trick Ukrainian Users into Running Malicious PowerShell

UAC-0145, a GRU-affiliated sub-cluster of Sandworm, exploited the 'ClickFix' social engineering technique by embedding fake CAPTCHA prompts on compromised websites that instructed victims to manually run malicious PowerShell commands — effectively bypassing traditional malware delivery defenses. The attack succeeded because users were deceived into trusting a familiar UI element (CAPTCHA) and voluntarily executing attacker-controlled code, circumventing endpoint protections that would normally block automated delivery. The campaign's use of Ethereum smart contracts for command-and-control obfuscation makes traditional domain-based blocking ineffective, highlighting the evolving sophistication of state-sponsored threat actors. This matters because it demonstrates that even technically aware users can be socially engineered, and that defenders must anticipate novel C2 channels outside conventional network indicators.

Tactical Insight

Immediate actions

  • Block or restrict PowerShell execution for standard (non-administrative) user accounts via Group Policy or endpoint management tools.
  • Deploy browser-level controls or endpoint security rules that alert on clipboard-injection patterns associated with ClickFix-style attacks.
  • Audit and harden all public-facing websites your organization controls to detect unauthorized script injections or iframe modifications.

Detection measures

  • Monitor and alert on anomalous PowerShell execution events, particularly those spawned from browser processes (e.g., chrome.exe, msedge.exe calling powershell.exe).
  • Implement DNS and network-layer inspection capable of flagging traffic to blockchain RPC endpoints (e.g., Ethereum nodes) from endpoints that have no legitimate business need.
  • Deploy SIEM correlation rules to detect multi-stage malware behavior patterns, such as reconnaissance scripts followed by outbound C2 beaconing.

Long-term improvements

  • Conduct regular, scenario-based security awareness training that specifically covers social engineering via fake UI elements like CAPTCHAs, verification prompts, and clipboard instructions.
  • Establish a threat intelligence program that ingests nation-state TTPs (e.g., Sandworm/UAC-0145 indicators) and translates them into actionable detection rules.
  • Implement application allowlisting to prevent unauthorized executables and scripts from running, regardless of how they are triggered.