Наталя ХандусенкоHot News
20 July 2026, 11:10
2026-07-20
Russian hackers infect Ukrainian devices with viruses using fake CAPTCHAs
Russian state hackers are using the notorious ClickFix scheme to trick users in Ukraine into infecting their devices with data-stealing viruses.
According to CERT-UA, the group behind these attacks is UAC-0145. This is a division of the well-known hacker group Sandworm, which is subordinate to the game.
Russian state hackers are using the notorious ClickFix scheme to trick users in Ukraine into infecting their devices with data-stealing viruses.
According to CERT-UA, the group behind these attacks is UAC-0145. This is a division of the well-known hacker group Sandworm, which is subordinate to the game.
In these attacks, attackers were found to be using fake CAPTCHA checks on compromised websites that instruct potential victims to execute a PowerShell command in the terminal, The Hacker News reports .
"The aforementioned command, as an example, could have been intended to download and save a VBS file to the Startup directory; one of the variants of such a program was called GHETTOVIBE," CERT-UA noted.
The attacks also involve the use of SCOUTCURL, a PowerShell script that performs basic reconnaissance, gathering information about the infected machine. Other malware detected on the affected endpoints include:
FLUIDLEECH and LOADLOOP, which act as loaders, with the former disguised as software to remove computer viruses. FREAKYPOLL is a backdoor written in Python.
It is estimated that at least 10 websites were compromised in this campaign between June and July 2026. In addition to using Cloaking.House, a traffic filtering service that allows different pages to be shown to different visitors, the attackers also used a custom tool called SMARTAXE to dynamically change the content of a web page depending on the site visitor and display a CAPTCHA check.
To embed CAPTCHA content into a web page, the EtherHiding technique is used. It allows you to retrieve the domain name of a remote resource from an Ethereum smart contract using the address specified in the source code.
CERT-UA notes that other attack techniques that attackers used to infiltrate devices were also discovered. Among them is the introduction of backdoors on Android devices by distributing APK files through messengers disguised as security tools. The malware embedded in the APK file is a fully-functional backdoor codenamed COWARDDUCK, which is capable of covertly collecting the following data:
contacts;
files with certain extensions (".conf", ".json", ".ovpn", ".txt", ".doc", ".docx", ".xls", ".xlsx", ".pptx", ".zip" and ".rar") from the following directories: "DCIM", "Documents", "Downloads", "Images" and "Alarms";
real-time geolocation.
In parallel, the malware uses the Dropbox cloud service API to upload files, while it receives commands or data from an external server or from legitimate sites such as steamcommunity[.]com.