UAC-0145 Uses ClickFix and Fake CAPTCHA to Compromise Devices in Ukraine

Colleagues, I’d like to draw your attention to a cybersecurity and cyberwarfare development.
CERT-UA has linked UAC-0145, associated with Sandworm, to a ClickFix-based campaign. Threat actors replace CAPTCHA prompts on compromised websites and trick victims into running a PowerShell command.
This is how they deliver loaders and backdoors, while also collecting system information. Android APKs disguised as security tools were also identified, carrying the COWARDDUCK backdoor.
Why it matters: social engineering remains one of the most effective infection vectors, and trust in CAPTCHA and “security tools” often works against users.
How do you verify such scenarios in your environment?
#cybersecurity #malware #threatintel #SOC


Latest comments
No comments yet.