UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

July 19, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Ukrainian government and civilian entities
Incident: A state-sponsored campaign using social engineering and compromised websites to deliver data-stealing malware.
Impact: Theft of sensitive documents, real-time geolocation tracking, and full remote control of infected endpoints.
Attacker: UAC-0145 (Sandworm / GRU)
Analysis: The actor UAC-0145 is employing a sophisticated chain that uses compromised websites and fake CAPTCHA prompts to force users to run PowerShell commands. They are utilizing ‘EtherHiding’ to obscure C2 domains via Ethereum smart contracts and deploying a suite of loaders and backdoors. Additionally, the campaign extends to mobile platforms via malicious APKs disguised as security tools.
Recommendations: Educate users against executing terminal commands provided by web prompts.; Implement strict monitoring and blocking of unauthorized PowerShell and VBScript execution.; Enforce policies to disable the installation of apps from unknown sources on mobile devices.
Source: The Hacker News / CERT-UA

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *