discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.

By Ravie Lakshmanan·Jul 19·thehackernews.com·3 min read

Intelligence analysis by Llama

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware
Image: thehackernews.com

Threat actors have been found to leverage fake CAPTCHA checks on compromised websites that instruct prospective targets to execute a PowerShell command in the terminal, which downloads and saves a VBS file in the Startup autorun directory.

Why it matters

This development highlights the evolving tactics of Russian state-sponsored threat actors, who are increasingly using social engineering techniques like ClickFix to deliver malware and compromise devices.

Imagine you're browsing a website, and it asks you to solve a CAPTCHA puzzle. But instead of just a puzzle, the website is actually trying to trick you into downloading a malicious program that can steal your data. This is what's happening with the ClickFix technique, where hackers are using fake CAPTCHA puzzles to deliver malware to unsuspecting users.

Analysis

A New Social Engineering Technique Emerges

The recent activity attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's primary foreign military intelligence agency, marks a departure from prior campaigns that have made use of trojanized installers for Microsoft Windows or Office containing a built-in backdoor or through bogus antivirus software shared via the Signal messaging app.

In these attacks, threat actors have been found to leverage fake CAPTCHA checks on compromised websites that instruct prospective targets to execute a PowerShell command in the terminal. The command, as an example, could be intended for downloading and saving a VBS file in the Startup autorun directory; one of the variants of such a program was called GHETTOVIBE.

The attacks also involve the use of SCOUTCURL, a PowerShell script that performs basic reconnaissance by harvesting details about the infected machine. Some of the other malicious programs found in the infected endpoints are as follows - FLUIDLEECH and LOADLOOP, which act as loaders, with the former masquerading as software for removing computer viruses. FREAKYPOLL, a Python backdoor

The Use of ClickFix

The use of ClickFix by the Kremlin-backed hacking crew marks a departure from prior campaigns that have made use of trojanized installers for Microsoft Windows or Office containing a built-in backdoor or through bogus antivirus software shared via the Signal messaging app. ClickFix continues to be an effective social engineering technique for malware delivery across the cyber threat landscape, with bad actors leveraging it to distribute OXLOADER, Mistic, SCMBANKER, ClickLock Stealer, TELEPUZ, and ACR Stealer.

The Impact on Ukrainian Targets

The attacks have been found to have infected at least 10 websites between June and July 2026. The threat actors have been found to use a bespoke tool called SMARTAXE to dynamically alter the content of a web page depending on the site visitor and display a CAPTCHA check. The CAPTCHA content to be injected into the web page employs the EtherHiding technique to retrieve the domain name of the remote resource from an Ethereum smart contract using an address specified in the source code.

Conclusion

The use of ClickFix by Russian state-sponsored threat actors highlights the evolving tactics of these groups, who are increasingly using social engineering techniques to deliver malware and compromise devices. The attacks have been found to have infected at least 10 websites between June and July 2026, and the threat actors have been found to use a bespoke tool called SMARTAXE to dynamically alter the content of a web page depending on the site visitor and display a CAPTCHA check.

Key points

  • Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.
  • The attacks involve the use of fake CAPTCHA checks on compromised websites that instruct prospective targets to execute a PowerShell command in the terminal.
  • The command, as an example, could be intended for downloading and saving a VBS file in the Startup autorun directory; one of the variants of such a program was called GHETTOVIBE.
  • The attacks also involve the use of SCOUTCURL, a PowerShell script that performs basic reconnaissance by harvesting details about the infected machine.
  • Some of the other malicious programs found in the infected endpoints are as follows - FLUIDLEECH and LOADLOOP, which act as loaders, with the former masquerading as software for removing computer viruses.
  • FREAKYPOLL, a Python backdoor has also been identified in the infected endpoints.
The Upside

If this development plays out positively, it could lead to a greater awareness of the ClickFix technique and its potential for delivering malware. This could prompt cybersecurity experts and organizations to develop more effective countermeasures to mitigate the risks associated with this technique.

The Downside

On the other hand, if this development plays out negatively, it could lead to a wider adoption of the ClickFix technique by hackers, resulting in a greater number of malware infections and data breaches. This could also lead to a decrease in trust in online services and a increase in cybersecurity costs for individuals and organizations.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagsai-agentscyber warfaredata theftmalwaremobile securitynation-statesocial engineeringthreat intelligencewebsite securitywindows

Author

Ravie Lakshmanan

Intelligence analysis by

Llama

Published

Jul 19, 2026

Source

thehackernews.com

Share

Topics

ai-agentscyber warfaredata theftmalwaremobile securitynation-statesocial engineeringthreat intelligencewebsite securitywindows

Related

More from this desk

Jul 19·bleepingcomputer.com

Hackers Abuse ViPNet Software to Target Russian Govt Agencies

Hackers are abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. The campaign, dubbed HelloNet, has been active since at least May and has impacted organizations in various sectors.

Jul 19·thehackernews.com

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026.

Jul 18·bleepingcomputer.com

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

7-Zip has released a security update to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files.

Jul 18·bleepingcomputer.com

WordPress Core 'wp2shell' RCE flaws get public exploits, patch now

WordPress Core has been hit with critical 'wp2shell' remote code execution vulnerabilities, tracked as CVE-2026-63030 and CVE-2026-60137. Public exploits have been released, making it essential for administrators to patch their sites immediately.