Sandworm hackers have a CAPTCHA trick for Ukrainians
Sandworm, a hacking group linked to Russia's military intelligence, is using a sophisticated CAPTCHA trick to trick Ukrainian targets into installing malware on their computers. The group employs a 'ClickFix' technique, directing users to fake CAPTCHA screens that prompt them to execute PowerShell commands, downloading malware like GhettoVibe and ScoutCurl. This tactic, alongside traditional social engineering methods targeting Android devices and leveraging messaging apps, has been used to gain access to Ukrainian government networks and launch destructive attacks.
Sandworm, a hacking group associated with Russia's military intelligence agency, the GRU, has shifted its initial access methods in Ukraine. Ukraine’s computer emergency response team (CERT-UA) reported observing a new tactic this spring and summer: a ‘ClickFix’ technique. In this method, the Sandworm group directs Ukrainian targets to compromised websites displaying a fake CAPTCHA security check. Instead of verifying a user is human, the system instructs them to copy and paste a PowerShell command into their Windows computers.
This command downloads malware, including GhettoVibe, which is then followed by a reconnaissance tool called ScoutCurl. ScoutCurl collects information about the infected computer, such as system details, installed software, files, and browser data, to determine if further compromise is worthwhile. CERT-UA observed this ClickFix technique on over 10 compromised websites during June and July, but did not report the number of infected devices.
Despite this shift, Sandworm continues to utilize established social engineering techniques. The agency noted that the group targets Android devices with malware disguised as security applications, distributed through messaging apps. Once installed, this malware can secretly collect contacts, files, device information, and real-time location data.
For years, Sandworm has relied on distributing backdoored copies of Microsoft Windows and Office installers through torrent sites, allowing the group to quietly compromise victims who downloaded pirated software. In one instance, this method enabled the hackers to establish a foothold inside a Ukrainian government network before launching a destructive cyberattack against a central executive authority. The agency also reported that Sandworm has targeted victims through the Signal messaging app, convincing them to install bogus antivirus software, often spending weeks building trust with military personnel and other targets before requesting them to run malicious files, sometimes offering cash payments in exchange for following instructions.
Western governments and cybersecurity researchers have linked Sandworm to Russia's military intelligence agency, the GRU, and the group has been active since at least 2013, responsible for some of Russia’s most high-profile destructive cyberattacks, including attacks on Ukraine’s power grid.
