UAC-0145 Malware Alert: How Russian Hackers Use ClickFix CAPTCHAs to Target Ukraine (2026)

The world of cyber warfare is a complex and ever-evolving landscape, and the recent discovery of a Russian state-sponsored attack on Ukraine highlights the ongoing threat of sophisticated hacking techniques. The UAC-0145 group, a sub-cluster within the infamous Sandworm unit, has been leveraging the ClickFix strategy to infect Ukrainian devices with malware, showcasing the adaptability and resourcefulness of these threat actors. This attack is particularly intriguing as it marks a departure from previous campaigns, which relied on trojanized installers or bogus antivirus software. Instead, UAC-0145 has turned to the power of social engineering, using fake CAPTCHA checks to trick targets into executing malicious commands. What makes this technique particularly insidious is its ability to dynamically alter the content of a web page, depending on the site visitor. This level of customization makes it difficult for users to discern the malicious intent, as the CAPTCHA challenge appears legitimate to most. The use of the EtherHiding technique to retrieve the domain name of the remote resource from an Ethereum smart contract further adds to the sophistication of the attack. This technique, combined with the SCOUTCURL PowerShell script, allows the threat actors to perform basic reconnaissance and gather details about the infected machine. The malware embedded in the APK file is a full-featured backdoor called COWARDDUCK, which can clandestinely collect a wide range of sensitive information, including contacts, files, and geolocation data. The attack also involves the use of FLUIDLEECH and LOADLOOP, which act as loaders, with FLUIDLEECH masquerading as software for removing computer viruses. This multi-layered approach highlights the complexity and resourcefulness of the UAC-0145 group, which is affiliated with Russia's primary foreign military intelligence agency, the GRU. The use of ClickFix by the Kremlin-backed hacking crew is a significant development in the cyber threat landscape, as it continues to be an effective social engineering technique for malware delivery. This attack serves as a stark reminder of the ongoing threat of cyber warfare and the need for organizations and individuals to remain vigilant and proactive in protecting their digital assets. From my perspective, the use of fake CAPTCHA checks and the dynamic alteration of web page content are particularly insidious, as they exploit the trust that users place in these seemingly legitimate challenges. This attack also underscores the importance of user education and awareness in the fight against cyber threats. As we continue to see the evolution of cyber warfare, it is crucial to stay informed and take proactive steps to protect our digital lives. Personally, I think that the use of ClickFix by state-sponsored threat actors is a significant development in the cyber threat landscape, and it highlights the ongoing threat of sophisticated hacking techniques. The attack on Ukraine serves as a stark reminder of the need for organizations and individuals to remain vigilant and proactive in protecting their digital assets. What makes this attack particularly fascinating is the use of fake CAPTCHA checks and the dynamic alteration of web page content, which are designed to exploit the trust that users place in these seemingly legitimate challenges. This attack also underscores the importance of user education and awareness in the fight against cyber threats. From my perspective, the use of fake CAPTCHA checks and the dynamic alteration of web page content are particularly insidious, as they exploit the trust that users place in these seemingly legitimate challenges. This attack also raises a deeper question about the role of state-sponsored threat actors in the cyber threat landscape and the need for international cooperation in combating these threats. In my opinion, the use of ClickFix by the UAC-0145 group is a significant development in the cyber threat landscape, and it highlights the ongoing threat of sophisticated hacking techniques. The attack on Ukraine serves as a stark reminder of the need for organizations and individuals to remain vigilant and proactive in protecting their digital assets. What makes this attack particularly fascinating is the use of fake CAPTCHA checks and the dynamic alteration of web page content, which are designed to exploit the trust that users place in these seemingly legitimate challenges. This attack also underscores the importance of user education and awareness in the fight against cyber threats. A detail that I find especially interesting is the use of the EtherHiding technique to retrieve the domain name of the remote resource from an Ethereum smart contract. This technique, combined with the SCOUTCURL PowerShell script, allows the threat actors to perform basic reconnaissance and gather details about the infected machine. This raises a deeper question about the role of blockchain technology in the cyber threat landscape and the need for further research and development in this area. In conclusion, the attack by the UAC-0145 group on Ukraine highlights the ongoing threat of sophisticated hacking techniques and the need for organizations and individuals to remain vigilant and proactive in protecting their digital assets. The use of fake CAPTCHA checks and the dynamic alteration of web page content are particularly insidious, as they exploit the trust that users place in these seemingly legitimate challenges. This attack also underscores the importance of user education and awareness in the fight against cyber threats. As we continue to see the evolution of cyber warfare, it is crucial to stay informed and take proactive steps to protect our digital lives.

UAC-0145 Malware Alert: How Russian Hackers Use ClickFix CAPTCHAs to Target Ukraine (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Rubie Ullrich

Last Updated:

Views: 5939

Rating: 4.1 / 5 (72 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Rubie Ullrich

Birthday: 1998-02-02

Address: 743 Stoltenberg Center, Genovevaville, NJ 59925-3119

Phone: +2202978377583

Job: Administration Engineer

Hobby: Surfing, Sailing, Listening to music, Web surfing, Kitesurfing, Geocaching, Backpacking

Introduction: My name is Rubie Ullrich, I am a enthusiastic, perfect, tender, vivacious, talented, famous, delightful person who loves writing and wants to share my knowledge and understanding with you.