UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Russian state-sponsored actors, linked to the Sandworm group and GRU, are using a ClickFix social engineering tactic to deliver malware to Ukrainian devices. They are leveraging fake CAPTCHA checks on compromised websites to trick users into executing PowerShell commands, resulting in the installation of data-stealing malware like GHETTOVIBE and a full-featured backdoor called COWARDDUCK. The campaign involves a multi-pronged approach, including Android device backdooring and utilizing a bespoke tool called SMARTAXE to dynamically alter website content.
Russian state-sponsored threat actors, associated with the Sandworm group and GRU, are utilizing the ClickFix social engineering technique to deliver malware to Ukrainian devices. The tactic involves presenting fake CAPTCHA checks on compromised websites, prompting users to execute PowerShell commands and install malicious software. CERT-UA has linked this activity to UAC-0145, a sub-cluster within Sandworm.
“The mentioned command, as an example, could be intended for downloading and saving a VBS file in the Startup autorun directory; one of the variants of such a program was called GHETTOVIBE,” CERT-UA said in an alert.
The campaign involves a multi-pronged approach, including Android device backdooring by distributing APK files via messaging apps, disguised as security tools. The malware embedded in the APK file is a full-featured backdoor codenamed COWARDDUCK that can clandestinely collect details such as contacts, files matching certain extensions (”.conf”, “.json”, “.ovpn”, “.txt”, “.doc”, “.docx”, “.xls”, “.xlsx”, “.pptx”, “.zip”, and “.rar”) from directories like “DCIM,” “Documents,” “Downloads,” “Pictures,” and “Alarms,” as well as geolocation in real time.
COWARDDUCK also utilizes the Dropbox cloud service API to upload files and retrieve commands or data from an external server or legitimate sites like steamcommunity[.]com. The attackers have also been found to use a bespoke tool called SMARTAXE to dynamically alter the content of a web page depending on the site visitor and display a CAPTCHA check. The CAPTCHA content employs the EtherHiding technique to retrieve the domain name of the remote resource from an Ethereum smart contract using an address specified in the source code.
At least 10 websites are assessed to have been compromised as part of this campaign between June and July 2026. Besides taking advantage of Cloaking.House, a traffic filtering service, the attackers have been found to use a bespoke tool called SMARTAXE to dynamically alter the content of a web page depending on the site visitor and display a CAPTCHA check.
The disclosure comes as ClickFix continues to be an effective social engineering technique for malware delivery across the cyber threat landscape, with bad actors leveraging it to distribute OXLOADER, Mistic, SCMBANKER, ClickLock Stealer, TELEPUZ, and ACR Stealer.
