The Containment Era is here. →Explore

Executive Summary

In July 2026, the Russian state-sponsored hacking group UAC-0145, also known as Sandworm or APT44, launched a campaign targeting Ukrainian organizations. The attackers employed a technique called ClickFix, which involves fake CAPTCHA prompts on compromised websites. These prompts instructed users to execute PowerShell commands, leading to the installation of data-stealing malware such as GHETTOVIBE and SCOUTCURL. The campaign compromised at least ten websites and utilized tools like SMARTAXE to dynamically alter web content, displaying deceptive CAPTCHA checks. Additionally, the attackers distributed malicious Android APK files via messaging apps, deploying the COWARDDUCK backdoor to exfiltrate sensitive information from infected devices.

This incident underscores the evolving tactics of state-sponsored threat actors, who are increasingly adopting social engineering techniques traditionally associated with financially motivated cybercriminals. The use of ClickFix by UAC-0145 highlights the need for heightened vigilance and user education to recognize and avoid such deceptive tactics.

Why This Matters Now

The adoption of ClickFix by state-sponsored actors like UAC-0145 signifies a concerning shift in cyber warfare tactics, blending sophisticated state-level capabilities with deceptive social engineering methods. This evolution increases the risk of successful attacks against both individuals and organizations, emphasizing the urgency for enhanced cybersecurity awareness and defenses.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

ClickFix is a social engineering method where attackers use fake CAPTCHA prompts to trick users into executing malicious commands, leading to malware installation.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to execute malicious commands would likely be constrained, reducing the risk of initial compromise.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges would likely be constrained, reducing the risk of establishing persistence.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's ability to move laterally would likely be constrained, reducing the risk of accessing additional systems.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish command and control channels would likely be constrained, reducing the risk of maintaining communication with compromised systems.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing the risk of data loss.

Impact (Mitigations)

The attacker's ability to access confidential information and disrupt services would likely be constrained, reducing the overall impact of the attack.

Impact at a Glance

Affected Business Functions

  • Government Communications
  • Public Services
  • Critical Infrastructure Management
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Sensitive government communications and critical infrastructure data.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement within the network.
  • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
  • Utilize Threat Detection & Anomaly Response systems to identify and respond to unusual activities promptly.
  • Enforce East-West Traffic Security to secure internal communications and detect unauthorized access.
  • Apply Inline IPS (Suricata) to inspect and block malicious payloads in real-time.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image