Sandworm hackers have a CAPTCHA trick for Ukrainians
ID: 4ec06cb7-caf7-5fcd-a569-7fba9dc3ff92
STIX ID: report--4ec06cb7-caf7-5fcd-a569-7fba9dc3ff92
Feed Name: The Record from Recorded Future News
CERT-UA reports that Sandworm has shifted to using fake CAPTCHA (‘ClickFix’) prompts on compromised websites to trick Ukrainian users into pasting PowerShell commands that install malware. Observed payloads include the GhettoVibe initial drop, ScoutCurl reconnaissance, and loaders named FluidLeech and LoadLoop; the group also uses Android spyware, backdoored Windows/Office installers and Signal-based social engineering. Sandworm is linked to Russia’s GRU and has a history of destructive operations against Ukrainian targets; the ClickFix technique was seen on more than ten compromised sites in June–July.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
