BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Sandworm Uses ClickFix Fake CAPTCHA to Target Ukraine

Russian Sandworm hackers use fake CAPTCHAs to trick Ukrainians into installing malware.

  • Russian state-sponsored hackers from the Sandworm group are using fake CAPTCHA checks to trick Ukrainian targets into executing malware.
  • The campaign, attributed to sub-cluster UAC-0145, compromises at least 10 websites and deploys data-stealing tools like FLUIDLEECH and FREAKYPOLL.
  • Attackers also target Android devices with a backdoor called COWARDDUCK, which steals contacts, files, and real-time geolocation data.

Russian state-sponsored threat actors have deployed the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware, according to the Computer Emergency Response Team of Ukraine (CERT-UA). The activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with Russia’s GRU.

- Advertisement -

In these attacks, threat actors leverage fake CAPTCHA checks on compromised websites that instruct targets to execute a PowerShell command. CERT-UA said the command, for example, could download a VBS file called GHETTOVIBE into the Startup autorun directory. The attacks also use SCOUTCURL, a PowerShell script that performs reconnaissance on the infected machine.

Other malicious programs include FLUIDLEECH and LOADLOOP, which act as loaders, with the former masquerading as virus-removal software. A Python backdoor called FREAKYPOLL is also deployed. At least 10 websites were compromised between June and July 2026, and attackers used a traffic filtering service called Cloaking.House to serve different pages to different visitors.

They also used a bespoke tool named SMARTAXE to dynamically alter web page content and display the CAPTCHA check. The CAPTCHA injection employs the EtherHiding technique to retrieve a remote domain name from an Ethereum smart contract.

CERT-UA also identified the threat actor distributing APK files via messaging apps, disguised as security tools, to backdoor Android devices. The embedded malware, codenamed COWARDDUCK, collects contacts, files with specific extensions like “.conf” and “.json,” and real-time geolocation data. The malware uses the Dropbox cloud service API to upload files while retrieving commands from an external server or legitimate sites like steamcommunity[.]com.

- Advertisement -

The use of ClickFix by Kremlin-backed hackers marks a departure from prior campaigns using trojanized installers or bogus antivirus software. This disclosure comes as ClickFix remains an effective social engineering technique for distributing malware across the cyber threat landscape.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Coinbase launches UK derivatives with up to 50x leverage

Coinbase is launching futures, perpetuals, and options for professional investors in the UK, with...

South Korea expands crypto Travel Rule to all transfers

South Korea will eliminate the $700 threshold for crypto Travel Rule compliance, applying it...

Strategy sells 1,690 Bitcoin for $108.6 million

Strategy sold 1,690 Bitcoin for roughly $108.6 million last week, marking its second sale...

Trump Media Revamps Digital Asset Strategy After $238M Loss

Trump Media reported a $238 million net loss in Q2, largely due to $190.4...

Buterin: Ethereum’s New Roadmap Boosts Quantum Security, AI

Ethereum co-founder Vitalik Buterin says quantum resistance, privacy, and AI-assisted security have become greater...

Must Read

Ethereum Hosting: TOP 10 Companies to Buy Hosting With Ethereum

If you are looking for Ethereum Hosting, you've hit the jackpot. In this article, we will present the 10 Best companies to buy hosting...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading