UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.
Intelligence analysis by Llama

Threat actors have been found to leverage fake CAPTCHA checks on compromised websites that instruct prospective targets to execute a PowerShell command in the terminal, which downloads and saves a VBS file in the Startup autorun directory.
Imagine you're browsing a website, and it asks you to solve a CAPTCHA puzzle. But instead of just a puzzle, the website is actually trying to trick you into downloading a malicious program that can steal your data. This is what's happening with the ClickFix technique, where hackers are using fake CAPTCHA puzzles to deliver malware to unsuspecting users.
Analysis
A New Social Engineering Technique Emerges
The recent activity attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's primary foreign military intelligence agency, marks a departure from prior campaigns that have made use of trojanized installers for Microsoft Windows or Office containing a built-in backdoor or through bogus antivirus software shared via the Signal messaging app.
In these attacks, threat actors have been found to leverage fake CAPTCHA checks on compromised websites that instruct prospective targets to execute a PowerShell command in the terminal. The command, as an example, could be intended for downloading and saving a VBS file in the Startup autorun directory; one of the variants of such a program was called GHETTOVIBE.
The attacks also involve the use of SCOUTCURL, a PowerShell script that performs basic reconnaissance by harvesting details about the infected machine. Some of the other malicious programs found in the infected endpoints are as follows - FLUIDLEECH and LOADLOOP, which act as loaders, with the former masquerading as software for removing computer viruses. FREAKYPOLL, a Python backdoor
The Use of ClickFix
The use of ClickFix by the Kremlin-backed hacking crew marks a departure from prior campaigns that have made use of trojanized installers for Microsoft Windows or Office containing a built-in backdoor or through bogus antivirus software shared via the Signal messaging app. ClickFix continues to be an effective social engineering technique for malware delivery across the cyber threat landscape, with bad actors leveraging it to distribute OXLOADER, Mistic, SCMBANKER, ClickLock Stealer, TELEPUZ, and ACR Stealer.
The Impact on Ukrainian Targets
The attacks have been found to have infected at least 10 websites between June and July 2026. The threat actors have been found to use a bespoke tool called SMARTAXE to dynamically alter the content of a web page depending on the site visitor and display a CAPTCHA check. The CAPTCHA content to be injected into the web page employs the EtherHiding technique to retrieve the domain name of the remote resource from an Ethereum smart contract using an address specified in the source code.
Conclusion
The use of ClickFix by Russian state-sponsored threat actors highlights the evolving tactics of these groups, who are increasingly using social engineering techniques to deliver malware and compromise devices. The attacks have been found to have infected at least 10 websites between June and July 2026, and the threat actors have been found to use a bespoke tool called SMARTAXE to dynamically alter the content of a web page depending on the site visitor and display a CAPTCHA check.
Key points
- Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.
- The attacks involve the use of fake CAPTCHA checks on compromised websites that instruct prospective targets to execute a PowerShell command in the terminal.
- The command, as an example, could be intended for downloading and saving a VBS file in the Startup autorun directory; one of the variants of such a program was called GHETTOVIBE.
- The attacks also involve the use of SCOUTCURL, a PowerShell script that performs basic reconnaissance by harvesting details about the infected machine.
- Some of the other malicious programs found in the infected endpoints are as follows - FLUIDLEECH and LOADLOOP, which act as loaders, with the former masquerading as software for removing computer viruses.
- FREAKYPOLL, a Python backdoor has also been identified in the infected endpoints.
If this development plays out positively, it could lead to a greater awareness of the ClickFix technique and its potential for delivering malware. This could prompt cybersecurity experts and organizations to develop more effective countermeasures to mitigate the risks associated with this technique.
On the other hand, if this development plays out negatively, it could lead to a wider adoption of the ClickFix technique by hackers, resulting in a greater number of malware infections and data breaches. This could also lead to a decrease in trust in online services and a increase in cybersecurity costs for individuals and organizations.



