[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:uac-0145-uses-clickfix-captchas-to-infect-ukrainian-devices-wih-malware-mru6xdm6":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":14,"article_ids":15,"ioc_summary":17,"source_urls":18,"status":20,"expires_at":21,"created_at":22,"updated_at":23,"articles":24},"b7ef9ef1-2026-412d-89e3-ea903bc30208","UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware","uac-0145-uses-clickfix-captchas-to-infect-ukrainian-devices-wih-malware-mru6xdm6","Russian state-sponsored actor UAC-0145 is using fake CAPTCHA prompts on compromised websites to socially engineer Ukrainian targets into running malicious PowerShell commands. Multiple malware families including GHETTOVIBE, SCOUTCURL, and Android backdoor COWARDDUCK have been deployed, with command delivery obfuscated through Ethereum smart contracts. This is an active campaign targeting Ukrainian devices with direct RCE capability.","critical","advisory",[],[13],"GRU","Immediately hunt for PowerShell execution events preceded by browser activity to compromised websites. Block known IOCs for GHETTOVIBE, SCOUTCURL, FLUIDLEECH, LOADLOOP, and FREAKYPOLL. Scan Ukrainian user endpoints for lateral movement and persistence artifacts.",[16],"ac125f7e-1079-4962-a67d-144b94e35607",null,[19],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fuac-0145-uses-clickfix-captchas-to.html","active","2026-07-23T05:05:50.602+00:00","2026-07-21T05:05:53.525671+00:00","2026-07-21T05:10:07.375217+00:00",[25],{"id":16,"title":6,"url":19}]