
Ukraine’s Computer Emergency Response Team issued a warning this week that Sandworm, an advanced hacking division within Russia’s GRU military intelligence agency, has begun deploying Clickfix attacks against sensitive Ukrainian organizations.
Clickfix is a social-engineering technique that has gained popularity among cybercriminals over the past year. The attack works by displaying a fake CAPTCHA on compromised websites, prompting visitors to copy and paste a text string into their terminal. Unknown to the user, this text contains malicious scripts that execute upon entry, typically installing malware or stealing sensitive information. Ukrainian authorities identified at least ten compromised websites participating in the Clickfix campaign, which has been active since the spring and continued through the summer months.
The Sandworm campaign has successfully compromised at least one organization, with infected devices detected running FreakyPoll, a custom malware package associated with the group. In the documented attacks, users were presented with fake PowerShell commands disguised as CAPTCHA verification tools. Once executed, these scripts deployed various malicious programs, beginning with reconnaissance software designed to gather system information. Systems identified as high-value targets received additional backdoor malware for persistent access. The initial reconnaissance tool, known as GHETTOVIBE, was followed by SCOUTCURL, a PowerShell script that collected detailed information about infected computers, including hardware specifications, installed programs, browser data, and files.
The campaign utilized multiple malware variants including FreakyPoll, FluidLeech (disguised as antivirus software), and LoadLoop. Notably, attackers employed sophisticated techniques such as SMARTAXE, which dynamically alters website content for visitors by retrieving commands from blockchain smart contracts, adding an additional layer of complexity to the attack infrastructure.
Sandworm has historically relied on different infection methods, including distributing booby-trapped pirated software through torrent trackers and conducting extended social engineering conversations via encrypted messaging platforms like Signal. The advisory urged website administrators and hosting providers to implement monitoring for web shells, unauthorized browser extensions, and other indicators of system compromise.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI