← Back to Daily Briefing (#ClickFix)

UAC-0145, a sub-cluster of the GRU-linked Sandworm group, is employing "ClickFix" social engineering to compromise Ukrainian and global targets. Attackers use compromised websites to present fraudulent CAPTCHA prompts, tricking users into manually executing malicious PowerShell commands. Once established, the group deploys a multi-stage Windows payload suite—including GHETTOVIBE and FREAKYPOLL—and the COWARDDUCK Android backdoor. C2 resilience is achieved via SMARTAXE, which utilizes Ethereum smart contracts and the eth_call function for dynamic domain resolution. Data exfiltration targets Signal, WhatsApp, and browser credentials via Dropbox and RSYNC, facilitating high-impact intelligence collection.

  • Initial Access: ClickFix Social Engineering

    • Leverages compromised websites to display fake CAPTCHA challenges to targets.
    • Coerces users into copying and executing malicious PowerShell or Terminal commands to "verify" human identity.
    • Represents a tactical pivot from traditional malicious installers to high-conversion manual execution techniques.
  • Windows Payload Ecosystem: Multi-Stage Deployment

    • Deploys a tiered toolset: GHETTOVIBE for VBS-based persistence and SCOUTCURL for PowerShell reconnaissance.
    • Utilizes FLUIDLEECH and LOADLOOP as primary loaders for secondary stages.
    • Executes advanced backdoors including KALAMBUR, SUMBUR, TAMBUR, and the Python-based FREAKYPOLL (.pyc) agent.
  • Android Exploitation: COWARDDUCK Backdoor

    • Deploys the COWARDDUCK backdoor to target mobile devices and steal sensitive files.
    • Prioritizes the theft of DCIM images, documents (.docx, .xlsx), and OVPN configuration files.
    • Captures real-time geolocation and contacts, exfiltrating the data via the Dropbox API.
  • C2 Infrastructure: Blockchain-Based Evasion

    • SMARTAXE utilizes Ethereum blockchain smart contracts via the eth_call function to resolve C2 domains dynamically.
    • Implements Cloaking.House to filter traffic and ensure payloads are only delivered to high-value target profiles.
    • Obfuscates command-and-control traffic by abusing legitimate Steam Community and StockMemory domains.
  • Exfiltration and Intelligence Targets

    • Targets Ukrainian government, critical infrastructure, and civilian entities, with an increasing global footprint.
    • Exfiltrates sensitive Signal and WhatsApp messaging data using RSYNC and the Tor network.
    • Harvests browser credentials, system specifications, and local files for strategic intelligence operations.

Related posts

  1. techjacksolutions.com — ClickFix Loader Ecosystem Expands: BabaDeda, Lorem Ipsum, and Potemkin Loaders Targeting Education, Finance, and Enterprise
  2. techjacksolutions.com — ClickFix Lure Adopted by Lorem Ipsum Malware Campaign With Possible Vice Society Attribution
  3. SC Media — Russian hackers use fake CAPTCHA to infect Ukrainian targets
  4. bleepingcomputer.com — New ClickLock macOS malware traps users into revealing login password
  5. Expert In the Cloud — macOS Malware Forces Users to Reveal Login Passwords
  6. feeds.feedburner.com — UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
  7. serisec.com — Ukraine warns fake CAPTCHAs are being used to make you hack yourself
  8. Security Affairs — Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure
  9. gbhackers.com — NullReceiver Is Harder to Discover but Still Exposes a Reusable Attacker Wallet
  10. SC Media — North Korea linked to new NullReceiver C2 technique
  11. blackhatnews.tokyo — Sandworm、偽装WireGuard VPNクライアントでITプロを標的に
  12. blackhatnews.tokyo — Sandworm、偽の求人面接でトロイの木馬化したWireGuard VPNをIT担当者に配布
  13. Expert In the Cloud — Trojanized WireGuard VPN to Infect IT Professionals
  14. techjacksolutions.com — Sandworm / UAC-0145 (Multi-Platform Campaign, No Single Vendor), Vulnerability Rollup (2026-07-19)
  15. feeds.feedburner.com — ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures
  16. helpnetsecurity.com — New macOS malware steals passwords by posing as Apple’s crash-reporting tool
  17. The Record by Recorded Future — Sandworm hackers have a CAPTCHA trick for Ukrainians
  18. thecyberexpress.com — ClickFix Attacks Drive UAC-0145 Cyber Campaigns, CERT-UA Warns
  19. Reddit
  20. Socprime
  21. Anvilogic
  22. Techzine
  23. Meteoraweb
  24. Daily
  25. Forbes
  26. Scworld
  27. Infosecurity-magazine
  28. Securityboulevard
  29. Malwarebytes
  30. Macworld
  31. Microsoft
  32. Daily
  33. Bluevoyant
  34. Mallory
  35. Securitybrief
  36. Huntress
  37. Socradar
  38. Cloud
  39. Labs
  40. Malpedia
  41. Mallory
  42. Reddit
  43. Gbhackers
  44. Cybersecuritynews
  45. The Record by Recorded Future — Russian military hackers pose as recruiters to target Ukrainian IT workers
  46. feeds.feedburner.com — Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
  47. bleepingcomputer.com — Sandworm hackers target IT pros with trojanized WireGuard VPN client
  48. Mallory
  49. Zscaler
  50. Facebook
  51. Technoid
  52. En
  53. Reddit
  54. Cybersecurity-help
  55. Cisoseries
  56. Dark Reading — 'Lorem Ipsum' Malware Pivots to ClickFix Delivery

LINK COPIED TO CLIPBOARD