Executive Summary
In July 2026, the Russian state-sponsored hacking group UAC-0145, also known as Sandworm or APT44, launched a campaign targeting Ukrainian organizations. The attackers employed a technique called ClickFix, which involves fake CAPTCHA prompts on compromised websites. These prompts instructed users to execute PowerShell commands, leading to the installation of data-stealing malware such as GHETTOVIBE and SCOUTCURL. The campaign compromised at least ten websites and utilized tools like SMARTAXE to dynamically alter web content, displaying deceptive CAPTCHA checks. Additionally, the attackers distributed malicious Android APK files via messaging apps, deploying the COWARDDUCK backdoor to exfiltrate sensitive information from infected devices.
This incident underscores the evolving tactics of state-sponsored threat actors, who are increasingly adopting social engineering techniques traditionally associated with financially motivated cybercriminals. The use of ClickFix by UAC-0145 highlights the need for heightened vigilance and user education to recognize and avoid such deceptive tactics.
Why This Matters Now
The adoption of ClickFix by state-sponsored actors like UAC-0145 signifies a concerning shift in cyber warfare tactics, blending sophisticated state-level capabilities with deceptive social engineering methods. This evolution increases the risk of successful attacks against both individuals and organizations, emphasizing the urgency for enhanced cybersecurity awareness and defenses.
Attack Path Analysis
UAC-0145 initiated the attack by compromising legitimate websites to display fake CAPTCHA prompts, tricking users into executing malicious PowerShell commands. Upon execution, the malware gained elevated privileges to establish persistence and evade detection. The attackers then moved laterally within the network using tools like OpenSSH and Tor to access additional systems. They established command and control channels through DNS over HTTPS to maintain communication with compromised systems. Sensitive data, including messaging app data, was exfiltrated using RSYNC to attacker-controlled servers. The impact included unauthorized access to confidential information and potential disruption of services.
Kill Chain Progression
Initial Compromise
Description
UAC-0145 compromised legitimate websites to display fake CAPTCHA prompts, tricking users into executing malicious PowerShell commands.
MITRE ATT&CK® Techniques
Spearphishing Attachment
Malicious File
PowerShell
Registry Run Keys / Startup Folder
Web Protocols
Data from Local System
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity Verification and Authentication
Control ID: Identity
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Ukrainian government entities face direct targeting from Russian state-sponsored UAC-0145 using ClickFix CAPTCHAs for data exfiltration and lateral movement capabilities.
Defense/Space
Defense infrastructure vulnerable to Sandworm's encrypted traffic exploitation and east-west lateral movement attacks targeting critical military intelligence and operational data.
Information Technology/IT
IT organizations managing Ukrainian infrastructure at risk from state-sponsored espionage requiring enhanced egress security and zero trust segmentation controls.
Telecommunications
Ukrainian telecom providers face sophisticated threats to encrypted communications infrastructure requiring multicloud visibility and threat detection capabilities against state actors.
Sources
- UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malwarehttps://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.htmlVerified
- ClickFix Attacks Fuel UAC-0145 Cyber Campaigns In Ukrainehttps://thecyberexpress.com/clickfix-attacks-fuel-uac-0145-cyber-campaigns/Verified
- Now, even Russia’s most elite hackers are using Clickfix to infect deviceshttps://arstechnica.com/security/2026/07/now-even-russias-most-elite-hackers-are-using-clickfix-to-infect-devices/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to execute malicious commands would likely be constrained, reducing the risk of initial compromise.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained, reducing the risk of establishing persistence.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally would likely be constrained, reducing the risk of accessing additional systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels would likely be constrained, reducing the risk of maintaining communication with compromised systems.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing the risk of data loss.
The attacker's ability to access confidential information and disrupt services would likely be constrained, reducing the overall impact of the attack.
Impact at a Glance
Affected Business Functions
- Government Communications
- Public Services
- Critical Infrastructure Management
Estimated downtime: 7 days
Estimated loss: $500,000
Sensitive government communications and critical infrastructure data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to unusual activities promptly.
- • Enforce East-West Traffic Security to secure internal communications and detect unauthorized access.
- • Apply Inline IPS (Suricata) to inspect and block malicious payloads in real-time.



