Techtimes
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as ClickFix, has surged in use, with over ten compromised Ukrainian websites identified since June 2026. The attackers, attributed to the UAC-0145 sub-cluster of Sandworm, exploit users' trust in technical prompts, leading them to unwittingly install malware. The malware includes a reconnaissance tool called ScoutCurl, which gathers sensitive information from infected systems. The campaign represents a significant shift in Sandworm's tactics, as they now hide their command-and-control infrastructure within the Ethereum blockchain, making it difficult to disrupt. The rise of ClickFix attacks has been alarming, with a reported 517% increase in such incidents during the first half of 2025. This trend poses a growing risk not only to Ukrainian users but also to computer users globally.
Key Points: • Sandworm hackers are using fake CAPTCHA prompts to trick users into executing malware. • Over ten Ukrainian websites have been compromised as part of this campaign since June 2026. • The command-and-control infrastructure is hidden within the Ethereum blockchain, complicating mitigation efforts.