logo

Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users

ID: 938c39db-b914-52ee-9f0a-4518cc5c0835

STIX ID: report--938c39db-b914-52ee-9f0a-4518cc5c0835

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-07-21

Date Updated: 2026-07-22

...
...

Ukraine's CERT-UA reports that the GRU-linked Sandworm (UAC-0145) group is using a 'ClickFix' technique—fake CAPTCHA prompts that induce users to run malicious PowerShell—leading to deployment of the ScoutCurl reconnaissance malware on over ten Ukrainian websites since June 2026; the campaign hides its command-and-control infrastructure in the Ethereum blockchain and CERT-UA notes a large increase in ClickFix incidents (reported 517% rise in H1 2025).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.