
Ukraine’s CERT center issued a warning that Sandworm, an advanced hacking division within Russia’s GRU military intelligence agency, has begun deploying Clickfix attacks against sensitive organizations in Ukraine. The technique, which has primarily been used by financially motivated cybercriminals over the past year, involves displaying fake CAPTCHA prompts on compromised websites that trick users into copying and pasting malicious code into their system terminals.
The Clickfix campaign attributed to Sandworm commenced in the spring and has continued through the summer months. Investigators identified at least one organization whose network was compromised when a connected device became infected with FreakyPoll, a custom malware package associated with Sandworm. Ukrainian authorities discovered ten compromised websites displaying PowerShell commands disguised as fake CAPTCHAs. Once users executed these scripts, the systems became infected with malicious Visual Basic scripts and other malware designed by Sandworm.
The infection chain typically begins with reconnaissance software that gathers information about the compromised device. Systems identified as valuable targets receive additional malware that establishes backdoor access. The advisory detailed how initial commands could load and save VBS files into startup directories, with variants named GHETTOVIBE. Secondary tools like SCOUTCURL, a PowerShell reconnaissance script, are then deployed to collect detailed system information including hardware specifications, installed programs, files, and browser data.
The campaign leverages multiple malware tools including FreakyPoll, a Python-based backdoor, FluidLeech, which masquerades as antivirus software, and LoadLoop. Attackers also employ SMARTAXE, specialized code that modifies website content by dynamically retrieving remote resource domain names through smart contracts. Additional techniques documented in the advisory include an Android-targeting backdoor tracked as CowardDuck that exfiltrates sensitive files to attacker-controlled servers.
The advisory noted that Sandworm has historically infected devices through torrent trackers seeded with booby-trapped pirated software and through extended social engineering conversations conducted over encrypted messaging platforms like Signal. Ukrainian authorities urged website administrators and hosting providers to monitor for indicators of compromise including web shells and unauthorized extensions.