BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Sandworm Uses ClickFix Fake CAPTCHA to Target Ukraine

Russian Sandworm hackers use fake CAPTCHAs to trick Ukrainians into installing malware.

  • Russian state-sponsored hackers from the Sandworm group are using fake CAPTCHA checks to trick Ukrainian targets into executing malware.
  • The campaign, attributed to sub-cluster UAC-0145, compromises at least 10 websites and deploys data-stealing tools like FLUIDLEECH and FREAKYPOLL.
  • Attackers also target Android devices with a backdoor called COWARDDUCK, which steals contacts, files, and real-time geolocation data.

Russian state-sponsored threat actors have deployed the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware, according to the Computer Emergency Response Team of Ukraine (CERT-UA). The activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with Russia’s GRU.

- Advertisement -

In these attacks, threat actors leverage fake CAPTCHA checks on compromised websites that instruct targets to execute a PowerShell command. CERT-UA said the command, for example, could download a VBS file called GHETTOVIBE into the Startup autorun directory. The attacks also use SCOUTCURL, a PowerShell script that performs reconnaissance on the infected machine.

Other malicious programs include FLUIDLEECH and LOADLOOP, which act as loaders, with the former masquerading as virus-removal software. A Python backdoor called FREAKYPOLL is also deployed. At least 10 websites were compromised between June and July 2026, and attackers used a traffic filtering service called Cloaking.House to serve different pages to different visitors.

They also used a bespoke tool named SMARTAXE to dynamically alter web page content and display the CAPTCHA check. The CAPTCHA injection employs the EtherHiding technique to retrieve a remote domain name from an Ethereum smart contract.

CERT-UA also identified the threat actor distributing APK files via messaging apps, disguised as security tools, to backdoor Android devices. The embedded malware, codenamed COWARDDUCK, collects contacts, files with specific extensions like “.conf” and “.json,” and real-time geolocation data. The malware uses the Dropbox cloud service API to upload files while retrieving commands from an external server or legitimate sites like steamcommunity[.]com.

- Advertisement -

The use of ClickFix by Kremlin-backed hackers marks a departure from prior campaigns using trojanized installers or bogus antivirus software. This disclosure comes as ClickFix remains an effective social engineering technique for distributing malware across the cyber threat landscape.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

South Korea eyes September launch for second phase of CBDC pilot

The Bank of Korea plans to launch the second phase of its wholesale CBDC...

Hugging Face Hacked by Autonomous AI Agent System

Open-source AI platform Hugging Face was hacked by an autonomous AI agent system that...

Allbridge Core pauses protocol after $1.65M security exploit

Allbridge paused its Allbridge Core protocol after a security incident drained $1.65 million from...

Critical Nginx Flat Allows Unauthenticated Remote Code Execution

F5 patched a critical nginx heap buffer overflow (CVE-2026-42533) rated 9.2 on CVSS v4,...

Saylor lists 110 reasons against Bitcoin BIP-110 fork

Strategy executive chairman Michael Saylor published a 3,700-word post with 110 reasons against Bitcoin...

Must Read

10 BEST Companies to Buy Hosting With Bitcoin And Crypto

If you are looking to buy hosting with bitcoin or cryptocurrency then you've come to the right place.I've done the research for you...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading