UAC-0145 Uses ClickFix CAPTCHAs to Deliver Malware to Ukrainian Devices
ID: 07fdb538-dbf5-5d16-af69-82cc731c563b
STIX ID: report--07fdb538-dbf5-5d16-af69-82cc731c563b
Feed Name: CosmicBytez Labs
**Executive Summary:** CERT‑UA reports that Russian state-sponsored actor UAC-0145 is deploying the ClickFix social‑engineering technique—fake CAPTCHA prompts that instruct victims to run PowerShell/Run commands—to deliver data‑stealing malware against Ukrainian individuals and organizations, enabling credential and document exfiltration; the advisory outlines why self‑execution bypasses many endpoint defenses and provides mitigations (user training, PowerShell restrictions, logging, EDR rules, and network monitoring).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
