
Ukraine’s CERT center has reported that Sandworm, an advanced hacking unit within Russia’s GRU military intelligence agency, has adopted the Clickfix attack technique to target sensitive organizations in Ukraine. The warning was issued Wednesday regarding campaigns that began in spring and continued through the summer months.
Clickfix operates as a social-engineering attack where compromised websites display a fake CAPTCHA requiring visitors to copy and paste text into their terminal. The text contains scripts that execute malicious actions upon entry, typically installing malware or stealing sensitive data. Ukrainian authorities identified at least 10 compromised websites using this method, with at least one organization experiencing network compromise when a connected device was found infected with FreakyPoll, a custom malware package used by Sandworm.
The attack chain begins with a PowerShell command disguised as a CAPTCHA verification step. Once executed, the script installs malicious Visual Basic scripts and other malware components. Initial infections typically involve reconnaissance tools that gather device information. Systems identified as important targets then receive additional malware designed to establish backdoor access. Specific tools documented in the campaign include GHETTOVIBE, SCOUTCURL, FluidLeech, and LoadLoop, each serving different functions in the attack sequence.
The attackers employed sophisticated techniques to display fake CAPTCHAs, utilizing both the Cloaking. House service and a custom tool called SMARTAXE that dynamically retrieves domain information from smart contracts. CERT-UA also documented other Sandworm techniques, including a backdoor tracked as CowardDuck that targets Android devices through deceptive application installation lures. The advisory noted that Sandworm has historically infected devices through compromised torrent trackers distributing booby-trapped pirated software and through extended social engineering conversations over encrypted messaging applications.
Ukrainian authorities called upon website administrators and hosting providers to monitor for web shells, unauthorized browser extensions, and other compromise indicators.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI