UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA Lures and EtherHiding to Deploy Multi-Stage GHETTOVIBE/SCOUTCURL/FLUIDLEECH/FREAKYPOLL/COWARDDUCK Toolset Against Ukraine — Threadlinqs Intelligence
As of 2026-07-19, UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA Lures and EtherHiding to Deploy Multi-Stage GHETTOVIBE/SCOUTCURL/FLUIDLEECH/FREAKYPOLL/COWARDDUCK Toolset Against Ukraine is a high-severity malware threat attributed to UAC-0145 (Sandworm (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1527 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: UAC-0145 (Sandworm · Russia · ESPIONAGE
UAC-0145, a sub-cluster of the Russian GRU's Sandworm (APT44/Seashell Blizzard/UAC-0002 lineage), compromised at least 10 legitimate websites in June-July 2026 to serve fake CAPTCHA (ClickFix) prompts
CERT-UA (advisory 6318437, published 2026-07-16) and CERT-UA-sourced reporting from The Record, The Hacker News, SOC Prime, The Cyber Express, and DKCERT describe a marked tactical shift by UAC-0145, a Sandworm/APT44 (GRU Unit 74455-lineage, also tracked as Seashell Blizzard and linked to the broader UAC-0002 cluster) sub-cluster, away from bespoke phishing lures and trojanized installers toward the ClickFix social-engineering technique. Beginning in spring 2026 and intensifying through June-July 2026, the group compromised more than ten legitimate websites and, via the Cloaking.House cloaking/traffic-filtering service, served fingerprinted Ukrainian visitors a fake browser CAPTCHA verification overlay. The overlay instructs the victim to press Win+R, paste a pre-loaded clipboard payload, and press Enter — executing an obfuscated PowerShell one-liner without any file ever touching disk at the point of execution.
The resulting intrusion chain deploys a modular toolset: GHETTOVIBE, a Visual Basic Script dropped into the Windows Startup directory for autorun persistence; SCOUTCURL, a PowerShell reconnaissance script that profiles the host (hardware/software inventory, installed security products, browser artifacts, local files) to triage victims before further staging; FLUIDLEECH, a loader that masquerades as antivirus-removal utility software to lower victim suspicion; and LOADLOOP, a secondary loader component. Later stages include FREAKYPOLL, a Python backdoor shipped as compiled .pyc bytecode, and — on Android, distributed via messaging apps (Signal) disguised as security/antivirus tooling — COWARDDUCK, a full-featured backdoor that harvests contacts, geolocation, and files matching sensitive extensions (.conf, .json, .ovpn, .txt, .doc, .docx, .xls, .xlsx, .pptx, .zip, .rar) from DCIM, Documents, Downloads, Pictures, and Alarms directories, exfiltrating via the Dropbox API.
The defining infrastructure innovation is SMARTAXE, a custom tool that dynamically alters compromised webpage content and resolves attacker-controlled redirect/payload domains by querying Ethereum and BNB Smart Chain smart contracts (a technique publicly dubbed EtherHiding by Google Threat Intelligence Group and previously observed in DPRK/UNC5342 Contagious Interview operations using the JADESNOW downloader). By embedding domain pointers in immutable, decentralized smart-contract storage, UAC-0145 removes any single attacker-controlled DNS or hosting resolver that defenders could seize or sinkhole — takedown would require contract-level blockchain intervention, which is not practically achievable. Observed UAC-0145 infrastructure includes the typosquatted Microsoft-lookalike domains office366[.]com and 365softupdate[.]com, plus abuse of legitimate services steamcommunity[.]com (C2 fallback/dead-drop resolver) and rsync/OpenSSH/Tor for lateral access and exfiltration staging. CERT-UA separately documented UAC-0145's parallel compromise vectors during the same window: torrent-distributed backdoored Windows/Office installers and Signal-based trust-building social engineering leading to bogus antivirus software execution — both feeding the same GHETTOVIBE/SCOUTCURL toolset. Related SOC Prime reporting also associates the wider UAC-0145/Sandworm cluster with KALAMBUR, SUMBUR, and TAMBUR post-access malware and prior Windows KMS-activator trojanization campaigns against Ukraine.
Targeting is concentrated on Ukrainian government networks, military personnel, and central executive authority systems, consistent with Sandworm's long-running (active since at least 2013) espionage and disruptive-access mission on behalf of Russian military intelligence. No CVE is associated with this campaign — the entire initial-access chain relies on social engineering (ClickFix) rather than software exploitation.
Weaknesses (CWE)
CWE-1021, CWE-451, CWE-506
Target sectors: government administration, military, defense, publicadministration
Target regions: ukraine, 151 - Eastern Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1584, T1583, T1587, T1189, T1566, T1204, T1059, T1059, T1059, T1569