VMTech
Discuss a project

UAC-0145 Uses ClickFix and Fake CAPTCHA to Compromise Devices in Ukraine

UAC-0145 Uses ClickFix and Fake CAPTCHA to Compromise Devices in Ukraine

Colleagues, I’d like to draw your attention to a cybersecurity and cyberwarfare development.

CERT-UA has linked UAC-0145, associated with Sandworm, to a ClickFix-based campaign. Threat actors replace CAPTCHA prompts on compromised websites and trick victims into running a PowerShell command.

This is how they deliver loaders and backdoors, while also collecting system information. Android APKs disguised as security tools were also identified, carrying the COWARDDUCK backdoor.

Why it matters: social engineering remains one of the most effective infection vectors, and trust in CAPTCHA and “security tools” often works against users.

How do you verify such scenarios in your environment?

#cybersecurity #malware #threatintel #SOC

Open analytics
On the site 12 views
min read 1 19.07.2026
On Instagram 5 views
On Instagram 1 reach
Instagram

UAC-0145 Uses ClickFix and Fake CAPTCHA to Compromise Devices in Ukraine

Open the post on Instagram ↗