Now, even Russia’s most elite hackers are using Clickfix to infect devices

by | Jul 27, 2026 | Technology

Now, even Russia's most elite hackers are using Clickfix to infect devices

Ukraine’s CERT center disclosed that Sandworm, an advanced cyber unit within Russia’s GRU military intelligence agency, has begun employing the Clickfix attack technique against sensitive organizations within the country. The technique, which has primarily been used by financially motivated criminal groups over the past year, involves displaying fake CAPTCHA prompts that trick users into copying and pasting malicious code into system terminals.

The Sandworm campaign utilizing Clickfix began in spring and has continued through summer, resulting in the compromise of at least one organization’s network. Ukrainian authorities identified 10 compromised websites displaying PowerShell commands disguised as CAPTCHA verification steps. Once users executed these scripts, the systems became vulnerable to installation of malicious Visual Basic scripts and various Sandworm malware packages, including FreakyPoll, a Python-based backdoor tool.

The attack chain typically begins with reconnaissance software that gathers device information. Machines identified as high-value targets receive additional malware for system backdooring. Other malware families deployed in these campaigns include FluidLeech, disguised as antivirus software, and LoadLoop. The attackers have incorporated sophisticated techniques using services like Cloaking. House for traffic filtering and a tool called SMARTAXE that dynamically retrieves remote content through smart contracts.

In addition to Clickfix attacks, Sandworm has employed several other infection methods documented by CERT-UA. The group has targeted Android devices through CowardDuck, a backdoor that assembles potentially sensitive files for exfiltration. Historically, Sandworm has distributed compromised software through torrent trackers and engaged targets in extended conversations over Signal before convincing them to install malware disguised as security applications.

Ukrainian authorities are urging website administrators and hosting providers to monitor for web shells, unauthorized extensions, and other indicators of system compromise.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI