VYPR
researchPublished Jul 19, 2026· 1 source

Russian State Hackers Use ClickFix CAPTCHAs to Target Ukraine with Malware

Russian state-sponsored threat actors, identified as UAC-0145 and linked to the Sandworm group, are employing a sophisticated social engineering tactic using fake CAPTCHA checks to trick Ukrainian organizations into downloading and executing malware.

Russian state-sponsored threat actors, identified as UAC-0145 and linked to the notorious Sandworm group, are actively targeting Ukrainian organizations with a novel attack vector that leverages fake CAPTCHA checks on compromised websites. This tactic, known as ClickFix, tricks unsuspecting users into executing malicious PowerShell commands, leading to the deployment of data-stealing malware and further compromise.

CERT-UA, the Computer Emergency Response Team of Ukraine, has attributed this campaign to UAC-0145, a sub-cluster of Sandworm, which is an advanced hacking unit affiliated with Russia's GRU. The attackers compromise legitimate websites and inject malicious code that presents users with a fake CAPTCHA challenge. Instead of verifying human interaction, these CAPTCHAs instruct users to execute a PowerShell command directly in their terminal.

One example of such a command, as detailed by CERT-UA, is designed to download and save a VBS file into the system's Startup directory, enabling persistence. Variants of this malicious program have been observed under names like GHETTOVIBE. The attacks also involve the use of SCOUTCURL, a PowerShell script designed to gather basic reconnaissance information about the infected machine, paving the way for more targeted attacks.

Beyond the initial infection, the threat actors have deployed a suite of malware, including FLUIDLEECH and LOADLOOP, which function as loaders for other malicious payloads. FLUIDLEECH, in particular, attempts to masquerade as legitimate antivirus software to evade detection. Additionally, FREAKYPOLL, a Python-based backdoor, has been identified, providing attackers with advanced control over compromised systems.

This campaign has impacted at least 10 websites between June and July 2026. The attackers are utilizing a traffic filtering service called Cloaking.House to serve different content to different visitors, enhancing their ability to evade detection. They also employ a custom tool named SMARTAXE to dynamically alter web page content based on the visitor, ensuring the malicious CAPTCHA is presented effectively. The CAPTCHA content itself uses the EtherHiding technique to retrieve remote resource domain names from an Ethereum smart contract.

In addition to the web-based attacks, CERT-UA has noted that UAC-0145 is also targeting Android devices. They distribute APK files disguised as security tools via messaging applications. These APKs contain a full-featured backdoor codenamed COWARDDUCK, capable of exfiltrating contacts, specific file types (documents, archives, configuration files), and real-time geolocation data. The malware leverages Dropbox's API for exfiltrating data and receiving commands.

The use of the ClickFix strategy by this GRU-affiliated group represents a shift from their previous methods, which often involved trojanized installers or bogus antivirus software. This tactic highlights the ongoing effectiveness of social engineering techniques in malware delivery, as ClickFix continues to be exploited by various threat actors to distribute a range of malware, including OXLOADER, Mistic, SCMBANKER, ClickLock Stealer, TELEPUZ, and ACR Stealer.

The campaign's focus on Ukrainian entities underscores the persistent geopolitical tensions and cyber warfare activities targeting the region. The sophisticated combination of social engineering, custom tools, and diverse malware families demonstrates the evolving capabilities of state-sponsored threat actors.

Synthesized by Vypr AI