- What: Russian hackers use fake CAPTCHA to infect Ukrainian targets
- Impact: Ukrainian users and organizations are at risk of malware infection through social engineering
Threat Intelligence Russian hackers use fake CAPTCHA to infect Ukrainian targets July 16, 2026 Share By SC Staff (Adobe Stock) Russian military intelligence hackers have begun using fake CAPTCHA prompts on compromised websites to trick Ukrainian targets into infecting their own computers, researchers have found. Ukraine's computer emergency response team (CERT-UA) observed a shift this spring and summer in how the Kremlin-backed hacking group Sandworm gains initial access to the systems of Ukrainian targets, with further coverage provided by The Record. The Sandworm group, linked to Russia's GRU, is employing the social engineering technique called ClickFix. Victims visiting compromised websites are presented with a fake CAPTCHA security check and instructed to copy and paste a PowerShell command into their Windows computers. This command downloads malware, such as GhettoVibe, which allows hackers to maintain access and deploy further malicious tools. Reconnaissance tools like ScoutCurl and malware loaders like FluidLeech and LoadLoop have also been observed. CERT-UA noted this technique on over a dozen compromised websites in June and July. Sandworm continues to use other methods, including targeting Android devices with malware disguised as security apps distributed via messaging apps, and distributing backdoored Windows and Office installers through torrent sites. In one instance, this led to a destructive cyberattack on a Ukrainian government network. The group also targets victims through Signal, building trust before asking them to run malicious files, sometimes offering payment. Source: The Record SC Staff Related Threat Intelligence Dutch police arrest suspects in international investment fraud scheme SC Staff July 16, 2026 The scheme, active since at least 2021, allegedly generated over 100 million euros per month by defrauding victims through fake investment platforms. Threat Intelligence Nigeria faces rising cybercrime losses despite falling fraud incidents SC Staff July 16, 2026 Nigeria is experiencing a complex cybersecurity landscape where reported fraud incidents have decreased by nearly 46% over the past four years, yet financial losses from cybercrime are on the rise, according to Check Point Software. Threat Intelligence New TuxBot v3 Evolution IoT botnet framework shows signs of AI development SC Staff July 16, 2026 Palo Alto Networks Unit 42 reported that while the LLM generated botnet code, it included an unremoved safety disclaimer. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Backdoor DNS Spoofing Deauthentication Attack Defacement Distributed Scans Domain Hijacking DumpSec Google Hacking Password Cracking Reconnaissance You can skip this ad in 5 seconds