Russian Hackers Use ClickFix CAPTCHAs to Target Ukraine: UAC-0145 Malware Attack (2026)

In the ongoing cyber warfare between Russia and Ukraine, a new development has emerged that showcases the evolving tactics of state-sponsored threat actors. The use of ClickFix CAPTCHAs by the UAC-0145 sub-cluster within Sandworm, a hacking unit affiliated with Russia's GRU, is a concerning strategy that warrants a deeper analysis.

The ClickFix Strategy

ClickFix is a social engineering technique that tricks targets into infecting their own devices with malware. In this case, Ukrainian targets are being lured into executing PowerShell commands, which download and save malicious files. The attackers employ a PowerShell script called SCOUTCURL for reconnaissance, gathering information about the infected machine.

What makes this particularly fascinating is the use of cloaking techniques. The attackers leverage Cloaking.House, a traffic filtering service, to serve different content to different visitors. This allows them to dynamically alter web pages and display CAPTCHA checks, making it harder to detect and mitigate the threat.

Malware Arsenal

The malware used in these attacks includes FLUIDLEECH and LOADLOOP, which act as loaders, and FREAKYPOLL, a Python backdoor. These tools enable the threat actors to collect sensitive data, including contacts, files, and real-time geolocation information. The malware also utilizes the Dropbox cloud service API for file uploads and command retrieval.

From my perspective, the sophistication of these tools and the way they are integrated into the attack chain is a testament to the advanced capabilities of the Sandworm hacking unit.

Android Backdoors

In addition to the Windows-based attacks, the threat actors have targeted Android devices by distributing APK files disguised as security tools. The COWARDDUCK malware embedded in these files can clandestinely collect a wide range of data, further expanding the attackers' reach.

This raises a deeper question about the potential impact on mobile users, who may not be as aware of these threats as their desktop counterparts.

Departure from Previous Campaigns

The use of ClickFix by the Kremlin-backed hacking crew marks a shift from previous campaigns that relied on trojanized installers and bogus antivirus software. This evolution in tactics highlights the adaptability and resourcefulness of these threat actors.

Personally, I think it's crucial to stay vigilant and continuously adapt our defense strategies to counter these evolving threats.

Broader Implications

The ongoing cyber conflict between Russia and Ukraine serves as a reminder of the importance of cybersecurity in today's digital age. As state-sponsored threat actors continue to refine their tactics, it's essential to remain proactive and innovative in our defense mechanisms.

In conclusion, the use of ClickFix CAPTCHAs by UAC-0145 is a concerning development that requires our attention and a comprehensive response. By staying informed and adapting our strategies, we can better protect ourselves and our digital infrastructure.

Russian Hackers Use ClickFix CAPTCHAs to Target Ukraine: UAC-0145 Malware Attack (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Patricia Veum II

Last Updated:

Views: 5870

Rating: 4.3 / 5 (44 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Patricia Veum II

Birthday: 1994-12-16

Address: 2064 Little Summit, Goldieton, MS 97651-0862

Phone: +6873952696715

Job: Principal Officer

Hobby: Rafting, Cabaret, Candle making, Jigsaw puzzles, Inline skating, Magic, Graffiti

Introduction: My name is Patricia Veum II, I am a vast, combative, smiling, famous, inexpensive, zealous, sparkling person who loves writing and wants to share my knowledge and understanding with you.