Now, even Russia’s most elite hackers are using Clickfix to infect devices

by | Jul 30, 2026 | Technology

Now, even Russia's most elite hackers are using Clickfix to infect devices

Ukraine’s CERT center reported Wednesday that Sandworm, an advanced hacking unit within the GRU, Russia’s military intelligence arm, has adopted a technique called Clickfix to compromise devices at sensitive organizations in Ukraine. The attack method has become increasingly popular among financially motivated cybercriminals over the past year.

Clickfix operates by displaying a fake CAPTCHA on compromised websites that instructs visitors to copy text and paste it into a terminal window. The text actually contains malicious scripts that, when executed, install malware or exfiltrate sensitive data. Ukrainian authorities identified at least 10 compromised websites using this approach during spring and summer months. The campaigns resulted in confirmed network compromise of at least one organization, with infected devices found to contain FreakyPoll, a custom malware package developed by Sandworm.

The malicious scripts typically deploy a chain of malware tools with distinct purposes. Initial payloads include reconnaissance programs that gather information about compromised systems to assess their value as targets. Important devices then receive follow-on malware designed to establish persistent access. Additional malware in the arsenal includes FluidLeech, which masquerades as antivirus software, and LoadLoop. Sandworm also employs a tool called SMARTAXE that allows attackers to dynamically modify website content by retrieving commands from blockchain smart contracts, enabling them to change the displayed CAPTCHA without direct server access.

Sandworm has historically relied on other infection methods, including seeding torrent trackers with booby-trapped pirated software and conducting extended social-engineering conversations over encrypted messaging platforms to convince targets to install disguised malware. The group recently expanded its targeting to include Android devices through an operation tracked as CowardDuck, which lures users to install applications that exfiltrate sensitive files.

Ukrainian authorities advised website administrators and hosting providers to monitor for indicators of compromise, including web shells and unauthorized browser extensions.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI