Russian state sponsored threat actors have been linked to a new malware campaign targeting Ukrainian users through the ClickFix social engineering technique. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub cluster of Sandworm, an advanced hacking group associated with Russia’s military intelligence agency, GRU. Researchers found that the attackers compromised multiple websites and displayed fake CAPTCHA verification pages that instructed visitors to execute malicious PowerShell commands on their own systems, ultimately leading to malware infections and data theft.
CERT-UA stated that the malicious CAPTCHA pages appeared on compromised websites and convinced users to manually copy and run PowerShell commands through the Windows terminal. These commands downloaded and saved malicious Visual Basic Script files into the Startup directory to establish persistence on infected systems. One of the identified malware samples used in the campaign was named GHETTOVIBE. Researchers also observed the use of SCOUTCURL, a PowerShell based reconnaissance script that gathers information about compromised devices before additional malware is deployed. Other malicious tools identified during the investigation include FLUIDLEECH and LOADLOOP, which function as malware loaders, with FLUIDLEECH disguising itself as antivirus software. The attackers also deployed FREAKYPOLL, a Python based backdoor that enables continued remote access to infected systems. According to CERT-UA, at least ten websites were compromised between June and July 2026 as part of this campaign.
The investigation revealed that the attackers employed several advanced techniques to increase the effectiveness of the operation. They used Cloaking.House, a traffic filtering service that delivers different content depending on the visitor, along with a custom tool called SMARTAXE that dynamically modified web pages to display fake CAPTCHA challenges only to intended targets. Researchers also found that the injected CAPTCHA pages relied on the EtherHiding technique, retrieving the domain of the malicious server from an Ethereum smart contract specified within the source code. Beyond Windows systems, CERT-UA identified additional attacks targeting Android devices. The attackers distributed malicious APK files through messaging applications while disguising them as security tools. These applications contained a backdoor known as COWARDDUCK, which is capable of collecting contacts, files with commonly used document and configuration formats, and real time geolocation information from infected devices. The malware also uploaded stolen information through the Dropbox API while receiving commands from external servers and legitimate websites such as Steam Community.
According to CERT-UA, the campaign represents a shift in tactics compared to previous operations attributed to the same threat group. Earlier campaigns primarily relied on trojanized Microsoft Windows or Microsoft Office installers containing embedded backdoors or fake antivirus software distributed through messaging platforms such as Signal. The adoption of ClickFix demonstrates a growing reliance on social engineering techniques that persuade users to unknowingly compromise their own devices by executing malicious commands themselves. By combining compromised websites, deceptive CAPTCHA verification pages, custom malware, and Android backdoors, the attackers created a multi platform campaign designed to steal sensitive information while maintaining persistent access to targeted systems across different environments.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.