Now, even Russia’s most elite hackers are using Clickfix to infect devices

by | Aug 9, 2026 | Technology

Now, even Russia's most elite hackers are using Clickfix to infect devices

Ukraine’s CERT center has disclosed that Sandworm, an advanced hacking unit within Russia’s GRU military intelligence agency, has adopted Clickfix attacks to target sensitive organizations in Ukraine. The campaign began in the spring and continued through the summer months.

Clickfix operates by displaying fake CAPTCHA challenges on compromised websites that trick users into copying and pasting malicious code into their device terminals. The technique had previously been employed primarily by financially motivated cybercriminals but is now being weaponized by the state-sponsored group. Ukrainian authorities identified at least 10 compromised websites participating in the campaign and confirmed the infection of at least one organization’s network with FreakyPoll, a custom malware package associated with Sandworm.

The attack chain begins with reconnaissance tools that gather device information to determine targets of interest. Higher-value machines receive additional backdoor malware packages. The malware toolkit includes FreakyPoll, a Python-based backdoor; FluidLeech, disguised as antivirus software; LoadLoop; and reconnaissance tools like SCOUTCURL that exfiltrate system data. The attackers also employ SMARTAXE, a program that dynamically generates remote domains through smart contracts to display malicious CAPTCHA pages to visitors.

Sandworm has deployed multiple infection vectors alongside Clickfix, including Android-focused malware tracked as CowardDuck that collects sensitive files. The group has historically relied on distributing trojanized software through torrent trackers and conducting extended conversations over Signal messenger to socially engineer targets into installing malicious security applications.

Ukraine’s CERT center advised website administrators and hosting providers to monitor for web shells, unauthorized browser extensions, and other indicators of system compromise.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI