Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
ID: 938c39db-b914-52ee-9f0a-4518cc5c0835
STIX ID: report--938c39db-b914-52ee-9f0a-4518cc5c0835
Feed Name: ThreatCluster
Threat Score
Ukraine's CERT-UA reports that the GRU-linked Sandworm (UAC-0145) group is using a 'ClickFix' technique—fake CAPTCHA prompts that induce users to run malicious PowerShell—leading to deployment of the ScoutCurl reconnaissance malware on over ten Ukrainian websites since June 2026; the campaign hides its command-and-control infrastructure in the Ethereum blockchain and CERT-UA notes a large increase in ClickFix incidents (reported 517% rise in H1 2025).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
