ClickFix Attacks Drive UAC-0145 Cyber Campaigns, CERT-UA Warns
ID: 8d23423b-5998-5b19-811c-e118a95b2035
STIX ID: report--8d23423b-5998-5b19-811c-e118a95b2035
Feed Name: The Cyber Express
CERT-UA reports that UAC-0145 (aka Sandworm/APT44) has shifted in 2026 to using ClickFix fake CAPTCHA pages and social engineering as a primary initial-access vector, tricking victims into running PowerShell that deploys a range of malware (e.g., GHETTOVIBE, SCOUTCURL, FLUIDLEECH, KALAMBUR, FREAKYPOLL) and Android backdoors (COWARDDUCK); attackers use compromised sites (via Cloaking.House and SMARTAXE), blockchain lookups, legitimate services (OpenSSH, Tor, Steam, Dropbox) and RSYNC for persistence and exfiltration, with Microsoft confirming a global rise in ClickFix campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
