Russian state-backed cybercriminals have been identified using the notorious ClickFix technique to deceive Ukrainian users into self-infecting their systems with malware. This tactic is part of a broader cyber warfare strategy targeting key Ukrainian infrastructure.
UAC-0145 and Sandworm’s Role
The Computer Emergency Response Team of Ukraine (CERT-UA) has attributed these activities to UAC-0145, a subgroup within Sandworm, a sophisticated hacking unit linked to the GRU, Russia’s main foreign intelligence arm. This group has been utilizing fake CAPTCHA challenges on compromised sites to persuade users to execute dangerous PowerShell commands.
One such command is designed to download a VBS file into the Startup directory, enabling the malware known as GHETTOVIBE to run automatically. Additionally, the attackers deploy SCOUTCURL, a PowerShell script, to gather reconnaissance data from infected machines.
Malware and Attack Techniques
The malicious software arsenal used in these attacks includes FLUIDLEECH and LOADLOOP, which serve as loaders, and FREAKYPOLL, a Python-based backdoor. These programs are spread through at least 10 compromised websites between June and July 2026, illustrating the coordinated nature of the campaign.
The threat actors leverage Cloaking.House, a service that filters traffic to present different web pages to different visitors, and SMARTAXE, a tool that dynamically modifies web content to inject CAPTCHA tests using the EtherHiding method.
Broader Implications and Techniques
Beyond web-based attacks, the hackers employ additional methods, including infecting Android devices by masquerading malicious APK files as security applications. The backdoor, named COWARDDUCK, can secretly collect contacts, specific files, and real-time geolocation data from infected devices.
This malware uses the Dropbox API to upload stolen data, while commands can be received from external servers or legitimate sites like steamcommunity[.]com.
Conclusion and Future Outlook
The deployment of ClickFix by Russian hackers signifies a shift from previous methods involving altered Microsoft software installers or fake antivirus tools. This revelation underscores ClickFix’s ongoing effectiveness in social engineering-driven malware distribution campaigns.
As the cyber threat landscape evolves, organizations must remain vigilant against such sophisticated tactics. Continued monitoring and responsive cybersecurity measures are crucial to mitigating these threats and safeguarding critical infrastructure.
