Russian Hackers Use Fake CAPTCHAs to Deploy Malware in Ukraine

Russian state-sponsored hackers have been exploiting fake CAPTCHA verifications to infiltrate Ukrainian systems with data-stealing malware. This tactic, known as ClickFix, involves deceiving users into executing malicious commands under the guise of resolving non-existent issues.

The Computer Emergency Response Team of Ukraine (CERT-UA) has identified these activities as the work of UAC-0145, a subgroup within Sandworm, a hacking unit linked to Russia’s GRU military intelligence agency. The attackers compromise legitimate websites to display fraudulent CAPTCHA prompts, instructing users to run specific PowerShell commands. Executing these commands initiates the download and installation of malware, such as GHETTOVIBE, into the system’s startup directory.

Once installed, the malware conducts reconnaissance by collecting information about the infected machine. Additional malicious programs deployed include FLUIDLEECH and LOADLOOP, which serve as loaders, and FREAKYPOLL, a Python-based backdoor.

Between June and July 2026, at least ten websites were compromised in this campaign. The attackers utilized Cloaking.House, a traffic filtering service, to serve different content to various visitors. They also employed a custom tool named SMARTAXE to dynamically inject CAPTCHA challenges into web pages. The CAPTCHA content was retrieved using the EtherHiding technique, which accesses domain names from Ethereum smart contracts specified in the source code.

In addition to targeting Windows systems, the hackers distributed malicious Android applications disguised as security tools through messaging apps. These APK files contained a backdoor called COWARDDUCK, capable of collecting contacts, specific file types, and real-time geolocation data. The malware used Dropbox’s API to upload stolen files and retrieved commands from external servers or legitimate sites like steamcommunity[.]com.

This campaign signifies a shift from previous methods employed by Russian hackers, such as using trojanized Windows or Office installers with built-in backdoors or distributing fake antivirus software via messaging apps like Signal.

The continued use of ClickFix highlights its effectiveness as a social engineering technique for malware delivery. Cybercriminals have leveraged it to distribute various malware strains, including OXLOADER, Mistic, SCMBANKER, ClickLock Stealer, TELEPUZ, and ACR Stealer.

As cyber threats evolve, it’s crucial for individuals and organizations to remain vigilant against sophisticated social engineering tactics like ClickFix. Regularly updating security protocols, educating users about potential threats, and implementing robust monitoring systems can help mitigate the risks associated with such deceptive techniques.