UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
ID: f488154e-0317-5c1c-94b9-7b762de736fe
STIX ID: report--f488154e-0317-5c1c-94b9-7b762de736fe
Feed Name: The Hacker News
**CERT-UA attributes a campaign to UAC-0145/Sandworm that compromised at least 10 websites and used fake CAPTCHA (ClickFix) lures to get victims to run PowerShell commands that download and persist data-stealing malware (e.g., GHETTOVIBE), reconnaissance scripts (SCOUTCURL), loaders (FLUIDLEECH, LOADLOOP), a Python backdoor (FREAKYPOLL), and an Android backdoor (COWARDDUCK); the actors employed Cloaking.House, SMARTAXE, EtherHiding (smart-contract domain retrieval), and abused legitimate services (Dropbox, steamcommunity.com) for C2 and exfiltration.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
