Find notable cyber news and cases, enriched with sources, timelines, and signals.

UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets

Campaign
First reported
Last updated
Happening score
H score 24
1 unique sources, 1 articles

Summary

Hide ▲

A UAC-0145 / Sandworm campaign is using ClickFix fake CAPTCHA pages on compromised websites to push malware onto Ukrainian targets, widening infection risk across at least 10 sites. The operation relies on PowerShell execution, page cloaking, and EtherHiding to steer victims toward malicious downloads. It also extends to Android lures packaged as security tools and a backdoor that can collect contacts, files, and geolocation.

Related Happenings

Mistic backdoor deployment via ClickFix and DLL side-loading

Malware Activity
H score22 First: 25.06.2026 11:54 Last: 25.06.2026 11:54 Sources 1

About this happening: The Mistic backdoor is being used in financially motivated attacks against organizations across insurance, education, IT, and professional services, raising the risk o...

Windows cryptocurrency clipper malware using USB LNK worming and Tor C2

Malware Activity
H score29 First: 18.06.2026 17:30 Last: 18.06.2026 17:30 Sources 1

About this happening: A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...

GammaWorm NTFS Alternate Data Streams propagation and backdoor activity

Malware Activity
H score40 First: 01.06.2026 14:00 Last: 01.06.2026 14:00 Sources 1

About this happening: The GammaWorm malware activity now shows a more covert stage that hides modules in NTFS Alternate Data Streams, helping it spread across Ukrainian networks while leavi...

GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy

Malware Activity
H score41 First: 29.05.2026 01:24 Last: 29.05.2026 01:24 Sources 1

About this happening: GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...

Grandoreiro and BTMOB banking trojan activity targeting Windows and Android

Malware Activity
H score25 First: 27.05.2026 19:10 Last: 27.05.2026 19:10 Sources 1

About this happening: BTMOB is an Android remote access trojan sold as malware-as-a-service on the clearweb and in private Telegram channels, with a builder that generates customize...

Timeline

  1. 19.07.2026 16:30 2 articles · 19h ago

    UAC-0145 uses ClickFix fake CAPTCHA pages against Ukrainian targets

    Initial Disclosure

    CERT-UA attributed a ClickFix campaign against Ukrainian targets to UAC-0145, a Sandworm sub-cluster linked to GRU, saying fake CAPTCHA checks on compromised websites lured victims into running a PowerShell command that installed data-stealing malware. The same activity involved EtherHiding, SCOUTCURL reconnaissance, loaders FLUIDLEECH and LOADLOOP, the Python backdoor FREAKYPOLL, and Android APK lures that delivered the COWARDDUCK backdoor.

    Show sources