UAC-0145 Sandworm ClickFix CAPTCHA and Ethereum-based SMARTAXE C2
UAC-0145, a sub-cluster of the GRU-linked Sandworm group, is employing "ClickFix" social engineering to compromise Ukrainian and global targets. Attackers use compromised websites to present fraudulent CAPTCHA prompts, tricking users into manually executing malicious PowerShell commands. Once established, the group deploys a multi-stage Windows payload suite—including GHETTOVIBE and FREAKYPOLL—and the COWARDDUCK Android backdoor. C2 resilience is achieved via SMARTAXE, which utilizes Ethereum smart contracts and the eth_call function for dynamic domain resolution. Data exfiltration targets Signal, WhatsApp, and browser credentials via Dropbox and RSYNC, facilitating high-impact intelligence collection.
Russian State-Sponsored Campaign Targeting Signal Messenger Accounts
Russian state-sponsored threat actors have launched a targeted campaign to hijack Signal Messenger accounts by exploiting vulnerabilities in the Public Switched Telephone Network (PSTN) rather than the application's encryption. This shift toward identity-layer exploitation demonstrates a sophisticated strategic pivot to bypass End-to-End Encryption (E2EE) by compromising the telephony-based authentication process used for account registration.