UAC-0145 Uses ClickFix CAPTCHA to Infect Ukrainian Devices with Malware

Russian state-sponsored threat actors have been spotted using the popular ClickFix strategy to trick targets in Ukraine into infecting their machines with data-stealing malware.
According to the Computer Emergency Response Team of Ukraine (CERT-UA), this work is said to have been created UAC-0145a sub-cluster within Sandworm, an advanced hacking unit affiliated with the GRU, Russia’s main foreign military intelligence agency.
In these attacks, malicious actors were found to be using fake CAPTCHA checks on compromised websites that instructed the target to run a PowerShell command in a terminal.
“The mentioned command, for example, could be intended to download and save a VBS file in the Startup autorun directory; one of the variants of such a program was called GHETTOVIBE,” CERT-UA said in a warning.
This attack also involves the use of SCOUTCURL, a PowerShell script that performs a basic search for information about the infected machine. Some of the malicious programs found at the end of the virus are as follows:
- FLUIDLEECH and LOADLOOP, which act as loaders, pre-emptively act as computer virus removal software.
- FREAKYPOLL, a Python backdoor
At least 10 websites were tested to be compromised as part of this campaign between June and July 2026. Besides taking advantage of Cloaking.House, a traffic filtering service that makes it possible to serve different pages to different visitors, the attackers were found to be using a dedicated tool called SMARTAXE to dynamically change the content of the website page and to perform CAPTCHA tests or web page checks.
The CAPTCHA content to be injected into the web page uses the EtherHiding process to find the domain name of the remote resource in the Ethereum smart contract using the address specified in the source code.

CERT-UA said it also identified a threat actor using other attack techniques to hack into devices, including rooting Android devices by distributing APK files through messaging apps, disguising them as security tools. The malware embedded in the APK file is a full backdoor code called COWARDDUCK that can secretly collect the following information –
- Contacts
- Files matching certain extensions (.conf,” “.json,” “.ovpn,” “.txt,” “.doc,” “.docx,” “.xls,” “.xlsx,” “.pptx,” “.zip,” and “.rar”) from the directories: “DCIM,” “Documents,” “Downloads,” “Images” and “alarms”
- Geolocation in real time
In parallel, the malware uses the Dropbox cloud service API to upload files, while receiving commands or data from an external server or legitimate sites such as steamcommunity.[.]com.
The use of ClickFix by a Kremlin-backed hacker group marks a departure from previous campaigns that used trojan-based installers for Microsoft Windows or Office containing a built-in backdoor or fake antivirus software shared with a messaging app.
This disclosure comes as ClickFix continues to be an effective social engineering method of malware delivery across the cyber threat landscape, with bad actors using it to distribute OXLOADER, Mistic, SCMBANKER, ClickLock Stealer, TELEPUZ, and ACR Stealer.



