Now, even Russia’s most elite hackers are using Clickfix to infect devices

by | Aug 19, 2026 | Technology

Now, even Russia's most elite hackers are using Clickfix to infect devices

Ukraine’s computer emergency response team disclosed that Sandworm, an advanced hacking unit within Russia’s GRU military intelligence agency, has adopted the Clickfix attack technique to target sensitive organizations. The campaign began in the spring and has continued through the summer, resulting in the compromise of at least one organization when a connected device was found infected with FreakyPoll, a custom malware package attributed to the group.

Clickfix operates by displaying a fake CAPTCHA prompt on compromised websites that instructs visitors to copy and paste text into their terminal. The text actually contains malicious scripts that, when executed, perform unauthorized actions on the device. Ukrainian authorities identified ten compromised websites displaying PowerShell commands disguised as CAPTCHA verification requests. Once users executed these scripts, the systems became vulnerable to installation of malicious Visual Basic scripts and other malware packages.

The attack chain typically begins with reconnaissance software that gathers information about infected devices. Systems deemed important then receive additional malware to establish backdoor access. The advisory detailed various malware components used in the campaign, including GHETTOVIBE, SCOUTCURL, FluidLeech, and LoadLoop. Researchers also identified SMARTAXE, a program code that allows attackers to dynamically alter webpage content by retrieving domain information from smart contracts, enabling the display of fraudulent CAPTCHAs.

Sandworm has employed multiple other attack methods documented by the advisory. One technique targets Android devices through lures designed to trick users into installing malicious apps tracked as CowardDuck, which exfiltrates sensitive files. Historically, the group distributed infected software through torrent trackers and engaged targets in extended conversations over encrypted messaging platforms before distributing malware disguised as security applications.

Ukrainian authorities recommended that website administrators and hosting providers implement monitoring for web shells, unauthorized browser extensions, and other indicators of system compromise.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI