
Ukraine’s CERT center has reported that Sandworm, an advanced hacking division within Russia’s GRU military intelligence agency, has begun employing Clickfix attacks against sensitive organizations. The technique, which had previously been used primarily by financially motivated criminals, involves compromised websites displaying fake CAPTCHA prompts that require visitors to copy and paste text into a terminal.
When users execute the copied scripts, malicious actions are triggered, typically resulting in malware installation or data theft. The campaign began in the spring and continued through the summer, with Ukrainian authorities identifying at least one organization whose network was compromised. Investigators discovered 10 websites displaying PowerShell commands disguised as CAPTCHAs and found evidence of FreakyPoll, a custom Sandworm malware package, on infected devices.
The attack chain typically begins with reconnaissance software gathering information about the compromised device. Machines identified as high-value targets then receive additional malware designed to establish persistent backdoor access. Initial payloads may include malicious Visual Basic scripts and tools such as GHETTOVIBE and SCOUTCURL, the latter being a PowerShell-based reconnaissance utility that collects data about system configuration, installed programs, files, and browser information.
Beyond Clickfix, Sandworm deployed other malware variants in the campaign, including FluidLeech, disguised as antivirus software, and LoadLoop. The group also used CowardDuck, which targets Android devices through deceptive app installations and collects sensitive files for exfiltration. Notably, attackers enhanced the Clickfix infrastructure using a tool called SMARTAXE, which dynamically obtains attacker-controlled domains through smart contract calls, adding technical sophistication to the attack.
Historically, Sandworm infected devices through booby-trapped software distributed via torrent trackers and by establishing prolonged conversations with targets over encrypted messaging platforms before convincing them to install trojans disguised as security applications. Ukrainian authorities have advised website administrators and hosting providers to monitor for web shells, unauthorized browser extensions, and other indicators of compromise.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI