Russian Hackers Use ClickFix CAPTCHAs to Target Ukraine: UAC-0145 Malware Attack (2026)

The world of cyber warfare is a complex and ever-evolving landscape, and the recent discovery of a sophisticated attack by the Russian state-sponsored group UAC-0145, or Sandworm, is a stark reminder of the ongoing threat. This group has been leveraging the infamous ClickFix strategy to infect Ukrainian devices with malware, marking a significant shift in their tactics. What makes this particularly fascinating is the group's ability to adapt and evolve, using fake CAPTCHA checks and other clever methods to trick targets into executing malicious commands. In my opinion, this highlights the importance of staying vigilant and up-to-date with the latest attack vectors, as well as the need for robust security measures to protect against such threats. The attack involved the use of fake CAPTCHA checks on compromised websites, which instructed targets to execute a PowerShell command in the terminal. This command was designed to download and save a VBS file in the Startup autorun directory, which could then be used to execute further malicious actions. What many people don't realize is that this is just one of many tactics used by state-sponsored groups to gain access to sensitive information and systems. The use of fake CAPTCHA checks is a clever social engineering technique that takes advantage of users' trust in legitimate websites and services. From my perspective, this attack serves as a stark reminder of the importance of user education and awareness in the fight against cyber threats. The attackers also used a bespoke tool called SMARTAXE to dynamically alter the content of a web page depending on the site visitor and display a CAPTCHA check. This tool, combined with the use of Cloaking.House, a traffic filtering service, allowed the attackers to serve different pages to different visitors and increase the chances of success. One thing that immediately stands out is the sophistication and adaptability of the attackers. The use of SMARTAXE and Cloaking.House, as well as the fake CAPTCHA checks, demonstrates a high level of technical expertise and a willingness to experiment with new techniques. This raises a deeper question: how can we better prepare for and defend against such evolving threats? The attack also involved the use of SCOUTCURL, a PowerShell script that performed basic reconnaissance by harvesting details about the infected machine. This script, along with other malicious programs found in the infected endpoints, such as FLUIDLEECH and LOADLOOP, acted as loaders and backdoors, allowing the attackers to gain further access to the system. What this really suggests is that the attackers were not just looking for a single point of entry, but rather a way to establish a persistent presence on the target system. The use of ClickFix by the Kremlin-backed hacking crew marks a departure from prior campaigns that have made use of trojanized installers for Microsoft Windows or Office containing a built-in backdoor or through bogus antivirus software shared via the Signal messaging app. This shift in tactics highlights the group's ability to adapt and evolve, and the need for security professionals to stay ahead of the curve. In my opinion, this attack serves as a wake-up call for organizations and individuals alike to take a more proactive approach to cybersecurity. The use of ClickFix continues to be an effective social engineering technique for malware delivery across the cyber threat landscape, with bad actors leveraging it to distribute a variety of malicious programs, including OXLOADER, Mistic, SCMBANKER, ClickLock Stealer, TELEPUZ, and ACR Stealer. This highlights the importance of staying vigilant and up-to-date with the latest attack vectors, as well as the need for robust security measures to protect against such threats. In conclusion, the attack by UAC-0145 serves as a stark reminder of the ongoing threat of cyber warfare and the need for a proactive approach to cybersecurity. The use of ClickFix and other sophisticated techniques highlights the importance of staying vigilant and up-to-date with the latest attack vectors, as well as the need for robust security measures to protect against such threats. Personally, I think that this attack also serves as a wake-up call for organizations and individuals alike to take a more proactive approach to cybersecurity and to stay ahead of the curve in the face of evolving threats.

Russian Hackers Use ClickFix CAPTCHAs to Target Ukraine: UAC-0145 Malware Attack (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Mr. See Jast

Last Updated:

Views: 5602

Rating: 4.4 / 5 (55 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Mr. See Jast

Birthday: 1999-07-30

Address: 8409 Megan Mountain, New Mathew, MT 44997-8193

Phone: +5023589614038

Job: Chief Executive

Hobby: Leather crafting, Flag Football, Candle making, Flying, Poi, Gunsmithing, Swimming

Introduction: My name is Mr. See Jast, I am a open, jolly, gorgeous, courageous, inexpensive, friendly, homely person who loves writing and wants to share my knowledge and understanding with you.