Now, even Russia’s most elite hackers are using Clickfix to infect devices

by | Aug 3, 2026 | Technology

Now, even Russia's most elite hackers are using Clickfix to infect devices

Ukraine’s CERT center disclosed that Sandworm, an advanced hacking unit within Russia’s GRU military intelligence agency, has begun deploying Clickfix attacks against sensitive organizations within Ukraine. The technique, which had previously been used primarily by financially motivated cybercriminals, represents a notable shift in the tactics employed by state-sponsored threat actors.

Clickfix operates by displaying fake CAPTCHA prompts on compromised websites that instruct visitors to copy and paste text into their terminal or command line interface. The text actually contains malicious scripts that, when executed, initiate a chain of compromises. In the Sandworm campaign documented by Ukrainian authorities, the initial commands were designed to load and execute Visual Basic scripts and other malicious payloads. The intrusions began in the spring and persisted through the summer, with Ukrainian researchers identifying at least 10 compromised websites used in the campaign.

Once a device is compromised through the fake CAPTCHA, Sandworm deploys reconnaissance tools to assess the value of the infected system. The group uses several custom malware packages in these attacks, including FreakyPoll, a Python-based backdoor, along with GHETTOVIBE, SCOUTCURL, FluidLeech, and LoadLoop. SCOUTCURL operates as a PowerShell script that collects basic system information, application data, and browser histories before exfiltrating the data to attacker-controlled servers. Devices deemed important by the attackers receive follow-on malware that establishes persistent backdoor access.

The campaign also employed sophisticated technical infrastructure, including use of the Cloaking. House service and custom code called SMARTAXE to dynamically serve malicious content to targeted visitors. The researchers noted that Sandworm has deployed multiple infection vectors beyond Clickfix, including Android-targeting malware designated CowardDuck that collects sensitive files, alongside historical tactics involving booby-trapped torrent links and social engineering over encrypted messaging applications.

Ukrainian authorities recommended that website administrators and hosting providers implement monitoring for web shells, unauthorized browser extensions, and other indicators of compromise on their systems.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI