Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users

Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users

First seen 22 Jul 2026, 00:51 UTC BitdefenderTechtimeswww.infosecurity-magazine.comwww.elastic.cowww.microsoft.com+1 90% similarity 77.0

Article Content

Browse articles
ThreatCluster

Ukraine's CERT-UA reported that the Russian GRU-linked hacking group Sandworm is employing fake CAPTCHA prompts to trick users into executing malicious PowerShell commands on their devices. This method, known as ClickFix, has surged in use, with over ten compromised Ukrainian websites identified since June 2026. The attackers, attributed to the UAC-0145 sub-cluster of Sandworm, exploit users' trust in technical prompts, leading them to unwittingly install malware. The malware includes a reconnaissance tool called ScoutCurl, which gathers sensitive information from infected systems. The campaign represents a significant shift in Sandworm's tactics, as they now hide their command-and-control infrastructure within the Ethereum blockchain, making it difficult to disrupt. The rise of ClickFix attacks has been alarming, with a reported 517% increase in such incidents during the first half of 2025. This trend poses a growing risk not only to Ukrainian users but also to computer users globally.

Key Points: • Sandworm hackers are using fake CAPTCHA prompts to trick users into executing malware. • Over ten Ukrainian websites have been compromised as part of this campaign since June 2026. • The command-and-control infrastructure is hidden within the Ethereum blockchain, complicating mitigation efforts.

ThreatCluster AI

Timeline

2025-01-01
Surge in ClickFix attacks reported
ESET measured a 517% increase in ClickFix attacks during the first half of 2025, indicating a growing trend.
Techtimes
2026-07-19
CERT-UA issues advisory on fake CAPTCHA attacks
CERT-UA attributed the ongoing fake CAPTCHA campaign to UAC-0145, a sub-cluster of the Sandworm group.
Techtimes
2026-07-21
Media reports on Sandworm's new attack method
Both Techtimes and Bitdefender reported on the use of fake CAPTCHAs to execute malicious commands on user systems.
Bitdefender

Community

Browse all →