UAC-0145, a sub-cluster of the GRU-linked Sandworm group, is employing "ClickFix" social engineering to compromise Ukrainian and global targets. Attackers use compromised websites to present fraudulent CAPTCHA prompts, tricking users into manually executing malicious PowerShell commands. Once established, the group deploys a multi-stage Windows payload suite—including GHETTOVIBE and FREAKYPOLL—and the COWARDDUCK Android backdoor. C2 resilience is achieved via SMARTAXE, which utilizes Ethereum smart contracts and the eth_call function for dynamic domain resolution. Data exfiltration targets Signal, WhatsApp, and browser credentials via Dropbox and RSYNC, facilitating high-impact intelligence collection.
-
Initial Access: ClickFix Social Engineering
- Leverages compromised websites to display fake CAPTCHA challenges to targets.
- Coerces users into copying and executing malicious PowerShell or Terminal commands to "verify" human identity.
- Represents a tactical pivot from traditional malicious installers to high-conversion manual execution techniques.
-
Windows Payload Ecosystem: Multi-Stage Deployment
- Deploys a tiered toolset: GHETTOVIBE for VBS-based persistence and SCOUTCURL for PowerShell reconnaissance.
- Utilizes FLUIDLEECH and LOADLOOP as primary loaders for secondary stages.
- Executes advanced backdoors including KALAMBUR, SUMBUR, TAMBUR, and the Python-based FREAKYPOLL (.pyc) agent.
-
Android Exploitation: COWARDDUCK Backdoor
- Deploys the COWARDDUCK backdoor to target mobile devices and steal sensitive files.
- Prioritizes the theft of DCIM images, documents (.docx, .xlsx), and OVPN configuration files.
- Captures real-time geolocation and contacts, exfiltrating the data via the Dropbox API.
-
C2 Infrastructure: Blockchain-Based Evasion
- SMARTAXE utilizes Ethereum blockchain smart contracts via the
eth_callfunction to resolve C2 domains dynamically. - Implements Cloaking.House to filter traffic and ensure payloads are only delivered to high-value target profiles.
- Obfuscates command-and-control traffic by abusing legitimate Steam Community and StockMemory domains.
- SMARTAXE utilizes Ethereum blockchain smart contracts via the
-
Exfiltration and Intelligence Targets
- Targets Ukrainian government, critical infrastructure, and civilian entities, with an increasing global footprint.
- Exfiltrates sensitive Signal and WhatsApp messaging data using RSYNC and the Tor network.
- Harvests browser credentials, system specifications, and local files for strategic intelligence operations.
Related posts
- techjacksolutions.com — ClickFix Loader Ecosystem Expands: BabaDeda, Lorem Ipsum, and Potemkin Loaders Targeting Education, Finance, and Enterprise
- techjacksolutions.com — ClickFix Lure Adopted by Lorem Ipsum Malware Campaign With Possible Vice Society Attribution
- SC Media — Russian hackers use fake CAPTCHA to infect Ukrainian targets
- bleepingcomputer.com — New ClickLock macOS malware traps users into revealing login password
- Expert In the Cloud — macOS Malware Forces Users to Reveal Login Passwords
- feeds.feedburner.com — UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
- serisec.com — Ukraine warns fake CAPTCHAs are being used to make you hack yourself
- Security Affairs — Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure
- gbhackers.com — NullReceiver Is Harder to Discover but Still Exposes a Reusable Attacker Wallet
- SC Media — North Korea linked to new NullReceiver C2 technique
- blackhatnews.tokyo — Sandworm、偽装WireGuard VPNクライアントでITプロを標的に
- blackhatnews.tokyo — Sandworm、偽の求人面接でトロイの木馬化したWireGuard VPNをIT担当者に配布
- Expert In the Cloud — Trojanized WireGuard VPN to Infect IT Professionals
- techjacksolutions.com — Sandworm / UAC-0145 (Multi-Platform Campaign, No Single Vendor), Vulnerability Rollup (2026-07-19)
- feeds.feedburner.com — ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures
- helpnetsecurity.com — New macOS malware steals passwords by posing as Apple’s crash-reporting tool
- The Record by Recorded Future — Sandworm hackers have a CAPTCHA trick for Ukrainians
- thecyberexpress.com — ClickFix Attacks Drive UAC-0145 Cyber Campaigns, CERT-UA Warns
- Socprime
- Anvilogic
- Techzine
- Meteoraweb
- Daily
- Forbes
- Scworld
- Infosecurity-magazine
- Securityboulevard
- Malwarebytes
- Macworld
- Microsoft
- Daily
- Bluevoyant
- Mallory
- Securitybrief
- Huntress
- Socradar
- Cloud
- Labs
- Malpedia
- Mallory
- Gbhackers
- Cybersecuritynews
- The Record by Recorded Future — Russian military hackers pose as recruiters to target Ukrainian IT workers
- feeds.feedburner.com — Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
- bleepingcomputer.com — Sandworm hackers target IT pros with trojanized WireGuard VPN client
- Mallory
- Zscaler
- Technoid
- En
- Cybersecurity-help
- Cisoseries
- Dark Reading — 'Lorem Ipsum' Malware Pivots to ClickFix Delivery