Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Hackers Exploit ClickFix CAPTCHAs in Ukraine

Russian Hackers Exploit ClickFix CAPTCHAs in Ukraine

Posted on July 19, 2026 By CWS

Russian state-backed cybercriminals have been identified using the notorious ClickFix technique to deceive Ukrainian users into self-infecting their systems with malware. This tactic is part of a broader cyber warfare strategy targeting key Ukrainian infrastructure.

UAC-0145 and Sandworm’s Role

The Computer Emergency Response Team of Ukraine (CERT-UA) has attributed these activities to UAC-0145, a subgroup within Sandworm, a sophisticated hacking unit linked to the GRU, Russia’s main foreign intelligence arm. This group has been utilizing fake CAPTCHA challenges on compromised sites to persuade users to execute dangerous PowerShell commands.

One such command is designed to download a VBS file into the Startup directory, enabling the malware known as GHETTOVIBE to run automatically. Additionally, the attackers deploy SCOUTCURL, a PowerShell script, to gather reconnaissance data from infected machines.

Malware and Attack Techniques

The malicious software arsenal used in these attacks includes FLUIDLEECH and LOADLOOP, which serve as loaders, and FREAKYPOLL, a Python-based backdoor. These programs are spread through at least 10 compromised websites between June and July 2026, illustrating the coordinated nature of the campaign.

The threat actors leverage Cloaking.House, a service that filters traffic to present different web pages to different visitors, and SMARTAXE, a tool that dynamically modifies web content to inject CAPTCHA tests using the EtherHiding method.

Broader Implications and Techniques

Beyond web-based attacks, the hackers employ additional methods, including infecting Android devices by masquerading malicious APK files as security applications. The backdoor, named COWARDDUCK, can secretly collect contacts, specific files, and real-time geolocation data from infected devices.

This malware uses the Dropbox API to upload stolen data, while commands can be received from external servers or legitimate sites like steamcommunity[.]com.

Conclusion and Future Outlook

The deployment of ClickFix by Russian hackers signifies a shift from previous methods involving altered Microsoft software installers or fake antivirus tools. This revelation underscores ClickFix’s ongoing effectiveness in social engineering-driven malware distribution campaigns.

As the cyber threat landscape evolves, organizations must remain vigilant against such sophisticated tactics. Continued monitoring and responsive cybersecurity measures are crucial to mitigating these threats and safeguarding critical infrastructure.

The Hacker News Tags:Android backdoor, CAPTCHAs, CERT-UA, ClickFix, COWARDDUCK, cyber warfare, Cybersecurity, Malware, malware attacks, PowerShell, Russian hackers, Sandworm, SCOUTCURL, UAC-0145, Ukraine

Post navigation

Previous Post: NadMesh Botnet Targets AI Systems Using Shodan
Next Post: SonicWall Zero-Days Exploited for Root Access

Related Posts

Critical PAN-OS Flaw Exploited for Root Access Critical PAN-OS Flaw Exploited for Root Access The Hacker News
Hackers Exploit c-ares DLL Side-Loading to Bypass Security and Deploy Malware Hackers Exploit c-ares DLL Side-Loading to Bypass Security and Deploy Malware The Hacker News
GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs GlassWorm Malware Discovered in Three VS Code Extensions with Thousands of Installs The Hacker News
Cybersecurity Weekly: Proxy Networks and AI Threats Cybersecurity Weekly: Proxy Networks and AI Threats The Hacker News
How to Detect Phishing Attacks Faster: Tycoon2FA Example How to Detect Phishing Attacks Faster: Tycoon2FA Example The Hacker News
Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Malicious RubyGems Packages Threaten Developer Security
  • Critical WordPress Flaws WP2Shell Actively Exploited
  • Hugging Face AI Platform Breached by Autonomous AI
  • Critical NGINX Flaw Enables Remote Code Execution
  • Critical NGINX Bug Poses Remote Code Execution Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Malicious RubyGems Packages Threaten Developer Security
  • Critical WordPress Flaws WP2Shell Actively Exploited
  • Hugging Face AI Platform Breached by Autonomous AI
  • Critical NGINX Flaw Enables Remote Code Execution
  • Critical NGINX Bug Poses Remote Code Execution Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark