UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA Lures and EtherHiding to Deploy Multi-Stage GHETTOVIBE/SCOUTCURL/FLUIDLEECH/FREAKYPOLL/COWARDDUCK Toolset Against Ukraine
UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA (TL-2026-1527), also tracked as ClickFix EtherHiding Campaign, is a high-severity malware campaign, first published 2026-07-19. It is attributed to UAC-0145 (Russia) with high confidence, affects Microsoft Windows (Run dialog / PowerShell / Windows Terminal), maps to 31 MITRE ATT&CK techniques (T1005, T1020, T1021), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-1527
- Threat ID
- TL-2026-1527
- Also known as
- ClickFix EtherHiding Campaign, Sandworm CAPTCHA Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-19
- Last reviewed
- 2026-07-19
- Attribution
- UAC-0145
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government administration, military, defense, publicadministration
- Target regions
- ukraine, 151 - Eastern Europe
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA
Malware and tooling: COWARDDUCK, FLUIDLEECH, FREAKYPOLL, GHETTOVIBE, Kalambur, LOADLOOP, SCOUTCURL, SUMBUR, TAMBUR, Cloaking.House, SMARTAXE
UAC-0145, a sub-cluster of the Russian GRU's Sandworm (APT44/Seashell Blizzard/UAC-0002 lineage), compromised at least 10 legitimate websites in June-July 2026 to serve fake CAPTCHA (ClickFix) prompts that trick Ukrainian government, military, and central-executive-authority users into pasting and executing malicious PowerShell into the Windows Run dialog. The intrusion chain deploys the GHETTOVIBE VBS persistence dropper, SCOUTCURL PowerShell reconnaissance tool, FLUIDLEECH and LOADLOOP loaders (FLUIDLEECH masquerades as antivirus-removal software), the FREAKYPOLL Python (.pyc) backdoor, and the COWARDDUCK Android backdoor, alongside legitimate-tool abuse (OpenSSH port forwarding, Tor, rsync, Dropbox API exfiltration). The SMARTAXE component dynamically rewrites compromised-site content and resolves attacker infrastructure via EtherHiding — reading payload/redirect domains from Ethereum/BNB Smart Chain smart contracts — while the Cloaking.House traffic-filtering service screens visitors to serve the malicious CAPTCHA overlay only to intended Ukrainian targets and hide it from crawlers, researchers, and non-target geographies.
How UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA works
CERT-UA (advisory 6318437, published 2026-07-16) and CERT-UA-sourced reporting from The Record, The Hacker News, SOC Prime, The Cyber Express, and DKCERT describe a marked tactical shift by UAC-0145, a Sandworm/APT44 (GRU Unit 74455-lineage, also tracked as Seashell Blizzard and linked to the broader UAC-0002 cluster) sub-cluster, away from bespoke phishing lures and trojanized installers toward the ClickFix social-engineering technique. Beginning in spring 2026 and intensifying through June-July 2026, the group compromised more than ten legitimate websites and, via the Cloaking.House cloaking/traffic-filtering service, served fingerprinted Ukrainian visitors a fake browser CAPTCHA verification overlay. The overlay instructs the victim to press Win+R, paste a pre-loaded clipboard payload, and press Enter — executing an obfuscated PowerShell one-liner without any file ever touching disk at the point of execution.
The resulting intrusion chain deploys a modular toolset: GHETTOVIBE, a Visual Basic Script dropped into the Windows Startup directory for autorun persistence; SCOUTCURL, a PowerShell reconnaissance script that profiles the host (hardware/software inventory, installed security products, browser artifacts, local files) to triage victims before further staging; FLUIDLEECH, a loader that masquerades as antivirus-removal utility software to lower victim suspicion; and LOADLOOP, a secondary loader component. Later stages include FREAKYPOLL, a Python backdoor shipped as compiled .pyc bytecode, and — on Android, distributed via messaging apps (Signal) disguised as security/antivirus tooling — COWARDDUCK, a full-featured backdoor that harvests contacts, geolocation, and files matching sensitive extensions (.conf, .json, .ovpn, .txt, .doc, .docx, .xls, .xlsx, .pptx, .zip, .rar) from DCIM, Documents, Downloads, Pictures, and Alarms directories, exfiltrating via the Dropbox API.
The defining infrastructure innovation is SMARTAXE, a custom tool that dynamically alters compromised webpage content and resolves attacker-controlled redirect/payload domains by querying Ethereum and BNB Smart Chain smart contracts (a technique publicly dubbed EtherHiding by Google Threat Intelligence Group and previously observed in DPRK/UNC5342 Contagious Interview operations using the JADESNOW downloader). By embedding domain pointers in immutable, decentralized smart-contract storage, UAC-0145 removes any single attacker-controlled DNS or hosting resolver that defenders could seize or sinkhole — takedown would require contract-level blockchain intervention, which is not practically achievable. Observed UAC-0145 infrastructure includes the typosquatted Microsoft-lookalike domains office366[.]com and 365softupdate[.]com, plus abuse of legitimate services steamcommunity[.]com (C2 fallback/dead-drop resolver) and rsync/OpenSSH/Tor for lateral access and exfiltration staging. CERT-UA separately documented UAC-0145's parallel compromise vectors during the same window: torrent-distributed backdoored Windows/Office installers and Signal-based trust-building social engineering leading to bogus antivirus software execution — both feeding the same GHETTOVIBE/SCOUTCURL toolset. Related SOC Prime reporting also associates the wider UAC-0145/Sandworm cluster with KALAMBUR, SUMBUR, and TAMBUR post-access malware and prior Windows KMS-activator trojanization campaigns against Ukraine.
Targeting is concentrated on Ukrainian government networks, military personnel, and central executive authority systems, consistent with Sandworm's long-running (active since at least 2013) espionage and disruptive-access mission on behalf of Russian military intelligence. No CVE is associated with this campaign — the entire initial-access chain relies on social engineering (ClickFix) rather than software exploitation.
MITRE ATT&CK techniques used in TL-2026-1527
Collection
T1005 Data from Local System; T1025 Data from Removable Media; T1119 Automated Collection; T1417 Input Capture; T1517 Access Notifications
Exfiltration
T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1620 Reflective Code Loading
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution; T1569 System Services
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer; T1568 Dynamic Resolution
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1217 Browser Information Discovery; T1518 Software Discovery
Initial Access
T1189 Drive-by Compromise; T1566 Phishing
Persistence
T1547 Boot or Logon Autostart Execution
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1587 Develop Capabilities
Affected products and versions in UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA
- Microsoft — Windows (Run dialog / PowerShell / Windows Terminal)
Vulnerable versions: All supported Windows versions with PowerShell available - Google — Android OS (sideloaded APK ecosystem)
Vulnerable versions: All Android versions permitting sideloaded APK installation
Remediation for UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA
Immediate actions
- Block/monitor process creation where rundll32.exe, mshta.exe, powershell.exe, or cmd.exe are spawned directly from the Windows Run dialog (explorer.exe parent) with encoded/obfuscated command-line arguments.
- Deploy a behavioral EDR rule flagging clipboard-to-Run-dialog PowerShell execution patterns (Win+R paste-and-enter) — CERT-UA-referenced detections caught this class of activity within ~300ms of execution.
- Block known UAC-0145 infrastructure: office366[.]com, 365softupdate[.]com; alert on unexpected outbound connections to steamcommunity[.]com from non-Steam processes.
- Restrict/monitor outbound Dropbox API traffic and unsanctioned rsync/OpenSSH/Tor usage on endpoints, especially government and military networks.
- Block sideloaded APKs from messaging apps (Signal) purporting to be antivirus/security tools on managed Android fleets; enforce Play Protect / MDM app allowlisting.
Workarounds
- Disable or tightly restrict the Windows Run dialog (Win+R) and Windows Terminal for high-risk user populations via GPO where operationally feasible.
- Enforce browser/OS-level warnings or blocking of clipboard-injected PowerShell execution (Attack Surface Reduction rules covering Office/Script child-process launches).
Longer-term hardening
- Deploy network-layer inspection for JSON-RPC calls to Ethereum/BNB Smart Chain nodes (eth_call) originating from endpoint processes — a strong signal of EtherHiding-style C2 domain resolution.
- User-awareness training specifically covering ClickFix / fake-CAPTCHA social engineering (never paste-and-run clipboard content via Win+R).
- Harden Windows Startup/autorun locations with application allowlisting to block unsigned VBS/script persistence (GHETTOVIBE class).
- Expand CERT-UA IOC-sharing ingestion and threat-intel feeds covering Sandworm/UAC-0145 sub-clusters into SOC detection content.
Weaknesses (CWE) in UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA
CWE-1021, CWE-451, CWE-506
Timeline of UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA
- Sandworm (APT44/Seashell Blizzard), the GRU-linked parent cluster of UAC-0145, has been active in offensive cyber operations since at least 2013.
- Google Threat Intelligence Group reports DPRK-linked UNC5342 employing EtherHiding (JADESNOW downloader) since February 2026 in Contagious Interview operations — the technique later adopted by UAC-0145.
- CERT-UA observes UAC-0145 beginning a spring 2026 shift away from trojanized installers toward ClickFix-style fake-CAPTCHA social engineering.
- ClickFix CAPTCHA campaign intensifies through June 2026, with more than ten legitimate websites compromised to serve the fake verification overlay to Ukrainian visitors.
- SOC Prime publishes detection content covering UAC-0145's primary compromise vectors as of July 2026, including torrent, Signal, and ClickFix access paths.
- The Record from Recorded Future News publishes coverage of the Sandworm CAPTCHA campaign citing CERT-UA findings.
- CERT-UA publishes advisory #6318437 detailing the ClickFix campaign, EtherHiding-based SMARTAXE infrastructure, and the GHETTOVIBE/SCOUTCURL/FLUIDLEECH/LOADLOOP/FREAKYPOLL/COWARDDUCK toolset.
- Danish CERT (DKCERT) issues a public advisory summarizing the fake-CAPTCHA malware installation technique for a European audience.
- The Cyber Express reports on the ClickFix campaign, adding detail on KALAMBUR/SUMBUR/TAMBUR post-access malware and Steam Community C2 abuse.
- The Hacker News publishes summary coverage of the UAC-0145 ClickFix/EtherHiding campaign, the basis for this threat record.
Sources cited for UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA
- UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware
- Sandworm hackers have a CAPTCHA trick for Ukrainians
- CERT-UA: Sandworm turns to ClickFix attacks
- ClickFix Attacks Fuel UAC-0145 Cyber Campaigns In Ukraine
- UAC-0145 Uses Torrents, Signal, and ClickFix for Access
- Russian hackers use fake CAPTCHA to infect Ukrainian targets
- Falske CAPTCHA-tjek bruges til at få brugere til at installere malware
- DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains
- Sandworm APT Attacks Detection: Russian State-Sponsored Hackers Deploy Malicious Windows KMS Activators to Target Ukraine
- Sandworm APT Targets Ukrainian Users with Trojanized Microsoft KMS Activation Tools in Cyber Espionage Campaigns
Threats related to UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA
- ACSC Advisory — ClickFix Campaign Distributing Vidar Stealer via Compromised WordPress Sites Targeting Australian Infrastructure
- Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach French Justice-Sector Server
- Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2 Concealment, and Turla Collaboration Delivering Kazuar Backdoor (2025)
- Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access
- ClickFix Campaigns Evolve API-Driven Payload Delivery: Analysis of 3,000 Live Payloads Reveals New Evasion Techniques
Detection coverage for TL-2026-1527
As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1527 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.