UAC-0145, a sub-cluster of the GRU-linked Sandworm group, is employing "ClickFix" social engineering to compromise Ukrainian and global targets. Attackers use compromised websites to present fraudulent CAPTCHA prompts, tricking users into manually executing malicious PowerShell commands. Once established, the group deploys a multi-stage Windows payload suite—including GHETTOVIBE and FREAKYPOLL—and the COWARDDUCK Android backdoor. C2 resilience is achieved via SMARTAXE, which utilizes Ethereum smart contracts and the eth_call function for dynamic domain resolution. Data exfiltration targets Signal, WhatsApp, and browser credentials via Dropbox and RSYNC, facilitating high-impact intelligence collection.
-
Initial Access: ClickFix Social Engineering
- Leverages compromised websites to display fake CAPTCHA challenges to targets.
- Coerces users into copying and executing malicious PowerShell or Terminal commands to "verify" human identity.
- Represents a tactical pivot from traditional malicious installers to high-conversion manual execution techniques.
-
Windows Payload Ecosystem: Multi-Stage Deployment
- Deploys a tiered toolset: GHETTOVIBE for VBS-based persistence and SCOUTCURL for PowerShell reconnaissance.
- Utilizes FLUIDLEECH and LOADLOOP as primary loaders for secondary stages.
- Executes advanced backdoors including KALAMBUR, SUMBUR, TAMBUR, and the Python-based FREAKYPOLL (.pyc) agent.
-
Android Exploitation: COWARDDUCK Backdoor
- Deploys the COWARDDUCK backdoor to target mobile devices and steal sensitive files.
- Prioritizes the theft of DCIM images, documents (.docx, .xlsx), and OVPN configuration files.
- Captures real-time geolocation and contacts, exfiltrating the data via the Dropbox API.
-
C2 Infrastructure: Blockchain-Based Evasion
- SMARTAXE utilizes Ethereum blockchain smart contracts via the
eth_callfunction to resolve C2 domains dynamically. - Implements Cloaking.House to filter traffic and ensure payloads are only delivered to high-value target profiles.
- Obfuscates command-and-control traffic by abusing legitimate Steam Community and StockMemory domains.
- SMARTAXE utilizes Ethereum blockchain smart contracts via the
-
Exfiltration and Intelligence Targets
- Targets Ukrainian government, critical infrastructure, and civilian entities, with an increasing global footprint.
- Exfiltrates sensitive Signal and WhatsApp messaging data using RSYNC and the Tor network.
- Harvests browser credentials, system specifications, and local files for strategic intelligence operations.
Related posts
- techjacksolutions.com — ClickFix Loader Ecosystem Expands: BabaDeda, Lorem Ipsum, and Potemkin Loaders Targeting Education, Finance, and Enterprise
- techjacksolutions.com — ClickFix Lure Adopted by Lorem Ipsum Malware Campaign With Possible Vice Society Attribution
- SC Media — Russian hackers use fake CAPTCHA to infect Ukrainian targets
- bleepingcomputer.com — New ClickLock macOS malware traps users into revealing login password
- Expert In the Cloud — macOS Malware Forces Users to Reveal Login Passwords
- feeds.feedburner.com — UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
- feeds.feedburner.com — ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures
- helpnetsecurity.com — New macOS malware steals passwords by posing as Apple’s crash-reporting tool
- The Record by Recorded Future — Sandworm hackers have a CAPTCHA trick for Ukrainians
- thecyberexpress.com — ClickFix Attacks Drive UAC-0145 Cyber Campaigns, CERT-UA Warns
- Socprime
- Anvilogic
- Techzine
- Meteoraweb
- Daily
- Forbes
- Scworld
- Infosecurity-magazine
- Securityboulevard
- Malwarebytes
- Macworld
- Microsoft
- Daily
- Bluevoyant
- Mallory
- Securitybrief
- Huntress
- Socradar
- Cloud
- Labs
- Malpedia
- Dark Reading — 'Lorem Ipsum' Malware Pivots to ClickFix Delivery