< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-19T19:00:55+05:30

UAC-0145 Leverages ClickFix CAPTCHAs for Malware Distribution in Ukraine

UAC-0145, a Russian state-sponsored group linked to Sandworm, has been using fake ClickFix CAPTCHAs on compromised Ukrainian websites to deploy data-stealing malware like GHETTOVIBE and COWARDDUCK. The attacks involve techniques such as EtherHiding and SCOUTCURL, targeting both Windows and Android devices through social engineering and backdoor methods.

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.

According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's

Read original article

*** END OF TRANSMISSION ***