Back to advisories

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Russian state-sponsored actor UAC-0145 is using fake CAPTCHA prompts on compromised websites to socially engineer Ukrainian targets into running malicious PowerShell commands. Multiple malware families including GHETTOVIBE, SCOUTCURL, and Android backdoor COWARDDUCK have been deployed, with command delivery obfuscated through Ethereum smart contracts. This is an active campaign targeting Ukrainian devices with direct RCE capability.