Security News

Cybersecurity news aggregator

HIGH Attacks The Hacker News

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Russian state-sponsored group UAC-0145 (Sandworm) is compromising Ukrainian websites to deploy a "ClickFix" attack, where victims are tricked into executing a malicious PowerShell command via a fake CAPTCHA check, leading to the installation of data-stealing malware like GHETTOVIBE, LOADLOOP, and the COWARDDUCK Android backdoor.
Read Full Article →

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware  Ravie Lakshmanan  Jul 19, 2026 Malware / Cyber Warfare Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145 , a sub-cluster within Sandworm , an advanced hacking unit affiliated with GRU, Russia's primary foreign military intelligence agency. In these attacks, threat actors have been found to leverage fake CAPTCHA checks on compromised websites that instruct prospective targets to execute a PowerShell command in the terminal. "The mentioned command, as an example, could be intended for downloading and saving a VBS file in the Startup autorun directory; one of the variants of such a program was called GHETTOVIBE," CERT-UA said in an alert. The attacks also involve the use of SCOUTCURL, a PowerShell script that performs basic reconnaissance by harvesting details about the infected machine. Some of the other malicious programs found in the infected endpoints are as follows - FLUIDLEECH and LOADLOOP, which act as loaders, with the former masquerading as software for removing computer viruses. FREAKYPOLL, a Python backdoor At least 10 websites are assessed to have been compromised as part of this campaign between June and July 2026. Besides taking advantage of Cloaking.House, a traffic filtering service that makes it possible to serve different pages to different visitors, the attackers have been found to use a bespoke tool called SMARTAXE to dynamically alter the content of a web page depending on the site visitor and display a CAPTCHA check. The CAPTCHA content to be injected into the web page employs the EtherHiding technique to retrieve the domain name of the remote resource from an Ethereum smart contract using an address specified in the source code. CERT-UA said it also identified the threat actor using other attack techniques to break into devices, including backdooring Android devices by distributing APK files via messaging apps, by disguising them as security tools. The malware embedded in the APK file is a full-featured backdoor codenamed COWARDDUCK that can clandestinely collect the following details - Contacts Files matching certain extensions (".conf," ".json," ".ovpn," ".txt," ".doc," ".docx," ".xls," ".xlsx," ".pptx," ".zip," and ".rar") from the directories: "DCIM," "Documents," "Downloads," "Pictures," and "Alarms" Geolocation in real time In tandem, the malware uses the Dropbox cloud service API to upload files, while retrieving commands or data from an external server or from legitimate sites like steamcommunity[.]com. The use of ClickFix by the Kremlin-backed hacking crew marks a departure from prior campaigns that have made use of trojanized installers for Microsoft Windows or Office containing a built-in backdoor or through bogus antivirus software shared via the Signal messaging app. The disclosure comes as ClickFix continues to be an effective social engineering technique for malware delivery across the cyber threat landscape, with bad actors leveraging it to distribute OXLOADER , Mistic , SCMBANKER , ClickLock Stealer , TELEPUZ , and ACR Stealer . Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post. SHARE      Tweet  Share  Share  Share   Share on Facebook  Share on Twitter  Share on Linkedin  Share on Reddit  Share on Hacker News  Share on Email  Share on WhatsApp Share on Facebook Messenger  Share on Telegram SHARE  Android , Cyber warfare , data theft , Malware , mobile security , Nation-State , Social Engineering , Threat Intelligence , Website Security , Windows ⚡ Top Stories This Week URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code ⭐ Featured Resources What 200+ Security Teams Reveal About Using IP Intelligence in 2026 Get Hands-On SANS Training for Today’s Cyber Defense and Offensive Security Challenges See What’s Really Exposed Across Your IT, OT, IoT, Cloud, and Mobile Assets Get Gartner’s Guide to AI Agent Supervision and Runtime Controls

Share this article