UAC-0145 Leverages ClickFix CAPTCHAs for Malware Distribution in Ukraine
UAC-0145, a Russian state-sponsored group linked to Sandworm, has been using fake ClickFix CAPTCHAs on compromised Ukrainian websites to deploy data-stealing malware like GHETTOVIBE and COWARDDUCK. The attacks involve techniques such as EtherHiding and SCOUTCURL, targeting both Windows and Android devices through social engineering and backdoor methods.
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.
According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's
*** END OF TRANSMISSION ***