1.9 C
Canberra
Monday, July 20, 2026

UAC-0145 Makes use of ClickFix CAPTCHAs to Infect Ukrainian Units wih Malware


Ravie LakshmananJul 19, 2026Malware / Cyber Warfare

UAC-0145 Makes use of ClickFix CAPTCHAs to Infect Ukrainian Units wih Malware

Russian state-sponsored menace actors have been noticed leveraging the notorious ClickFix technique to trick Ukrainian targets into infecting their very own machines with data-stealing malware.

Based on the Laptop Emergency Response Staff of Ukraine (CERT-UA), the exercise has been attributed to UAC-0145, a sub-cluster inside Sandworm, a sophisticated hacking unit affiliated with GRU, Russia’s major international navy intelligence company.

In these assaults, menace actors have been discovered to leverage pretend CAPTCHA checks on compromised web sites that instruct potential targets to execute a PowerShell command within the terminal.

“The talked about command, for example, might be meant for downloading and saving a VBS file within the Startup autorun listing; one of many variants of such a program was referred to as GHETTOVIBE,” CERT-UA mentioned in an alert.

The assaults additionally contain the usage of SCOUTCURL, a PowerShell script that performs primary reconnaissance by harvesting particulars in regards to the contaminated machine. Among the different malicious packages discovered within the contaminated endpoints are as follows –

  • FLUIDLEECH and LOADLOOP, which act as loaders, with the previous masquerading as software program for eradicating pc viruses.
  • FREAKYPOLL, a Python backdoor

No less than 10 web sites are assessed to have been compromised as a part of this marketing campaign between June and July 2026. In addition to benefiting from Cloaking.Home, a visitors filtering service that makes it potential to serve completely different pages to completely different guests, the attackers have been discovered to make use of a bespoke instrument referred to as SMARTAXE to dynamically alter the content material of an online web page relying on the location customer and show a CAPTCHA verify.

The CAPTCHA content material to be injected into the online web page employs the EtherHiding method to retrieve the area title of the distant useful resource from an Ethereum sensible contract utilizing an handle specified within the supply code.

CERT-UA mentioned it additionally recognized the menace actor utilizing different assault strategies to interrupt into units, together with backdooring Android units by distributing APK recordsdata by way of messaging apps, by disguising them as safety instruments. The malware embedded within the APK file is a full-featured backdoor codenamed COWARDDUCK that may clandestinely accumulate the next particulars –

  • Contacts
  • Information matching sure extensions (“.conf,” “.json,” “.ovpn,” “.txt,” “.doc,” “.docx,” “.xls,” “.xlsx,” “.pptx,” “.zip,” and “.rar”) from the directories: “DCIM,” “Paperwork,” “Downloads,” “Photos,” and “Alarms”
  • Geolocation in actual time

In tandem, the malware makes use of the Dropbox cloud service API to add recordsdata, whereas retrieving instructions or information from an exterior server or from professional websites like steamcommunity[.]com.

Using ClickFix by the Kremlin-backed hacking crew marks a departure from prior campaigns which have made use of trojanized installers for Microsoft Home windows or Workplace containing a built-in backdoor or via bogus antivirus software program shared by way of the Sign messaging app.

The disclosure comes as ClickFix continues to be an efficient social engineering method for malware supply throughout the cyber menace panorama, with dangerous actors leveraging it to distribute OXLOADER, Mistic, SCMBANKER, ClickLock Stealer, TELEPUZ, and ACR Stealer.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

[td_block_social_counter facebook="tagdiv" twitter="tagdivofficial" youtube="tagdiv" style="style8 td-social-boxed td-social-font-icons" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjM4IiwiZGlzcGxheSI6IiJ9LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" custom_title="Stay Connected" block_template_id="td_block_template_8" f_header_font_family="712" f_header_font_transform="uppercase" f_header_font_weight="500" f_header_font_size="17" border_color="#dd3333"]
- Advertisement -spot_img

Latest Articles