- Russian state-sponsored hackers from the Sandworm group are using fake CAPTCHA checks to trick Ukrainian targets into executing malware.
- The campaign, attributed to sub-cluster UAC-0145, compromises at least 10 websites and deploys data-stealing tools like FLUIDLEECH and FREAKYPOLL.
- Attackers also target Android devices with a backdoor called COWARDDUCK, which steals contacts, files, and real-time geolocation data.
Russian state-sponsored threat actors have deployed the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware, according to the Computer Emergency Response Team of Ukraine (CERT-UA). The activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with Russia’s GRU.
In these attacks, threat actors leverage fake CAPTCHA checks on compromised websites that instruct targets to execute a PowerShell command. CERT-UA said the command, for example, could download a VBS file called GHETTOVIBE into the Startup autorun directory. The attacks also use SCOUTCURL, a PowerShell script that performs reconnaissance on the infected machine.
Other malicious programs include FLUIDLEECH and LOADLOOP, which act as loaders, with the former masquerading as virus-removal software. A Python backdoor called FREAKYPOLL is also deployed. At least 10 websites were compromised between June and July 2026, and attackers used a traffic filtering service called Cloaking.House to serve different pages to different visitors.
They also used a bespoke tool named SMARTAXE to dynamically alter web page content and display the CAPTCHA check. The CAPTCHA injection employs the EtherHiding technique to retrieve a remote domain name from an Ethereum smart contract.
CERT-UA also identified the threat actor distributing APK files via messaging apps, disguised as security tools, to backdoor Android devices. The embedded malware, codenamed COWARDDUCK, collects contacts, files with specific extensions like “.conf” and “.json,” and real-time geolocation data. The malware uses the Dropbox cloud service API to upload files while retrieving commands from an external server or legitimate sites like steamcommunity[.]com.
The use of ClickFix by Kremlin-backed hackers marks a departure from prior campaigns using trojanized installers or bogus antivirus software. This disclosure comes as ClickFix remains an effective social engineering technique for distributing malware across the cyber threat landscape.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
