Mazda CX5
Як зробити цифрову копію себе. Ось відео —>

Russian hackers infect Ukrainian devices with viruses using fake CAPTCHAs

Russian state hackers are using the notorious ClickFix scheme to trick users in Ukraine into infecting their devices with data-stealing viruses.

According to CERT-UA, the group behind these attacks is UAC-0145. This is a division of the well-known hacker group Sandworm, which is subordinate to the game.

Leave a comment
Russian hackers infect Ukrainian devices with viruses using fake CAPTCHAs

Russian state hackers are using the notorious ClickFix scheme to trick users in Ukraine into infecting their devices with data-stealing viruses.

According to CERT-UA, the group behind these attacks is UAC-0145. This is a division of the well-known hacker group Sandworm, which is subordinate to the game.

In these attacks, attackers were found to be using fake CAPTCHA checks on compromised websites that instruct potential victims to execute a PowerShell command in the terminal, The Hacker News reports .

"The aforementioned command, as an example, could have been intended to download and save a VBS file to the Startup directory; one of the variants of such a program was called GHETTOVIBE," CERT-UA noted.

The attacks also involve the use of SCOUTCURL, a PowerShell script that performs basic reconnaissance, gathering information about the infected machine. Other malware detected on the affected endpoints include:

FLUIDLEECH and LOADLOOP, which act as loaders, with the former disguised as software to remove computer viruses. FREAKYPOLL is a backdoor written in Python.

It is estimated that at least 10 websites were compromised in this campaign between June and July 2026. In addition to using Cloaking.House, a traffic filtering service that allows different pages to be shown to different visitors, the attackers also used a custom tool called SMARTAXE to dynamically change the content of a web page depending on the site visitor and display a CAPTCHA check.

To embed CAPTCHA content into a web page, the EtherHiding technique is used. It allows you to retrieve the domain name of a remote resource from an Ethereum smart contract using the address specified in the source code.

CERT-UA notes that other attack techniques that attackers used to infiltrate devices were also discovered. Among them is the introduction of backdoors on Android devices by distributing APK files through messengers disguised as security tools. The malware embedded in the APK file is a fully-functional backdoor codenamed COWARDDUCK, which is capable of covertly collecting the following data:

  • contacts;

  • files with certain extensions (".conf", ".json", ".ovpn", ".txt", ".doc", ".docx", ".xls", ".xlsx", ".pptx", ".zip" and ".rar") from the following directories: "DCIM", "Documents", "Downloads", "Images" and "Alarms";

  • real-time geolocation.

In parallel, the malware uses the Dropbox cloud service API to upload files, while it receives commands or data from an external server or from legitimate sites such as steamcommunity[.]com.

ClickFix forces users to run malware themselves under the guise of a security check
ClickFix forces users to run malware themselves under the guise of a security check
On the topic
ClickFix forces users to run malware themselves under the guise of a security check
PhantomCaptcha phishing campaign: Russian hackers target state administrations and organizations assisting Ukraine
PhantomCaptcha phishing campaign: Russian hackers target state administrations and organizations assisting Ukraine
On the topic
PhantomCaptcha phishing campaign: Russian hackers target state administrations and organizations assisting Ukraine
“This step is necessary to prove that I am not a bot.” ChatGPT AI agent easily passes the “I am not a robot” CAPTCHA
“This step is necessary to prove that I am not a bot.” ChatGPT AI agent easily passes the “I am not a robot” CAPTCHA
On the topic
“This step is necessary to prove that I am not a bot.” ChatGPT AI agent easily passes the “I am not a robot” CAPTCHA
Read the country's main IT news in our Telegram
Read the country's main IT news in our Telegram
On the topic
Read the country's main IT news in our Telegram

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.