UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets
Campaign
Summary
Hide ▲
Show ▼
A UAC-0145 / Sandworm campaign is using ClickFix fake CAPTCHA pages on compromised websites to push malware onto Ukrainian targets, widening infection risk across at least 10 sites. The operation relies on PowerShell execution, page cloaking, and EtherHiding to steer victims toward malicious downloads. It also extends to Android lures packaged as security tools and a backdoor that can collect contacts, files, and geolocation.
Related Happenings
Mistic backdoor deployment via ClickFix and DLL side-loading
Malware Activity
H score22
First: 25.06.2026 11:54
Last: 25.06.2026 11:54
Sources 1
About this happening:
The Mistic backdoor is being used in financially motivated attacks against organizations across insurance, education, IT, and professional services, raising the risk o...
Mistic backdoor deployment via ClickFix and DLL side-loading
Malware ActivityAbout this happening: The Mistic backdoor is being used in financially motivated attacks against organizations across insurance, education, IT, and professional services, raising the risk o...
Windows cryptocurrency clipper malware using USB LNK worming and Tor C2
Malware Activity
H score29
First: 18.06.2026 17:30
Last: 18.06.2026 17:30
Sources 1
About this happening:
A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...
Windows cryptocurrency clipper malware using USB LNK worming and Tor C2
Malware ActivityAbout this happening: A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...
GammaWorm NTFS Alternate Data Streams propagation and backdoor activity
Malware Activity
H score40
First: 01.06.2026 14:00
Last: 01.06.2026 14:00
Sources 1
About this happening:
The GammaWorm malware activity now shows a more covert stage that hides modules in NTFS Alternate Data Streams, helping it spread across Ukrainian networks while leavi...
GammaWorm NTFS Alternate Data Streams propagation and backdoor activity
Malware ActivityAbout this happening: The GammaWorm malware activity now shows a more covert stage that hides modules in NTFS Alternate Data Streams, helping it spread across Ukrainian networks while leavi...
GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy
Malware Activity
H score41
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...
GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy
Malware ActivityAbout this happening: GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...
Grandoreiro and BTMOB banking trojan activity targeting Windows and Android
Malware Activity
H score25
First: 27.05.2026 19:10
Last: 27.05.2026 19:10
Sources 1
About this happening:
BTMOB is an Android remote access trojan sold as malware-as-a-service on the clearweb and in private Telegram channels, with a builder that generates customize...
Grandoreiro and BTMOB banking trojan activity targeting Windows and Android
Malware ActivityAbout this happening: BTMOB is an Android remote access trojan sold as malware-as-a-service on the clearweb and in private Telegram channels, with a builder that generates customize...
Timeline
-
19.07.2026 16:30 2 articles · 19h ago
UAC-0145 uses ClickFix fake CAPTCHA pages against Ukrainian targets
Initial DisclosureCERT-UA attributed a ClickFix campaign against Ukrainian targets to UAC-0145, a Sandworm sub-cluster linked to GRU, saying fake CAPTCHA checks on compromised websites lured victims into running a PowerShell command that installed data-stealing malware. The same activity involved EtherHiding, SCOUTCURL reconnaissance, loaders FLUIDLEECH and LOADLOOP, the Python backdoor FREAKYPOLL, and Android APK lures that delivered the COWARDDUCK backdoor.
Show sources
- UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware — thehackernews.com — 19.07.2026 16:30
- UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware — thehackernews.com — 19.07.2026 16:30