Techtimes
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
Article Content
Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as ClickFix, has surged in use, with over ten compromised Ukrainian websites identified since June 2026. The attackers, attributed to the UAC-0145 sub-cluster of Sandworm, exploit users' trust in technical prompts, leading them to unwittingly install malware. The malware includes a reconnaissance tool called ScoutCurl, which gathers sensitive information from infected systems. The campaign represents a significant shift in Sandworm's tactics, as they now hide their command-and-control infrastructure within the Ethereum blockchain, making it difficult to disrupt. The rise of ClickFix attacks has been alarming, with a reported 517% increase in such incidents during the first half of 2025. This trend poses a growing risk not only to Ukrainian users but also to computer users globally.
Key Points: • Sandworm hackers are using fake CAPTCHA prompts to trick users into executing malware. • Over ten Ukrainian websites have been compromised as part of this campaign since June 2026. • The command-and-control infrastructure is hidden within the Ethereum blockchain, complicating mitigation efforts.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.