logo

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

ID: f488154e-0317-5c1c-94b9-7b762de736fe

STIX ID: report--f488154e-0317-5c1c-94b9-7b762de736fe

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-07-19

Date Updated: 2026-07-19

Author: [email protected] (The Hacker News)

...
...

**CERT-UA attributes a campaign to UAC-0145/Sandworm that compromised at least 10 websites and used fake CAPTCHA (ClickFix) lures to get victims to run PowerShell commands that download and persist data-stealing malware (e.g., GHETTOVIBE), reconnaissance scripts (SCOUTCURL), loaders (FLUIDLEECH, LOADLOOP), a Python backdoor (FREAKYPOLL), and an Android backdoor (COWARDDUCK); the actors employed Cloaking.House, SMARTAXE, EtherHiding (smart-contract domain retrieval), and abused legitimate services (Dropbox, steamcommunity.com) for C2 and exfiltration.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.