Threat reportThreat IntelligenceTL-2026-2393

UAC-0145 (Sandworm sub-cluster) ClickFix fake-CAPTCHA campaign against Ukrainian devices with EtherHiding C2 resolution

criticalACTIVE

UAC-0145 (Sandworm sub-cluster) ClickFix fake-CAPTCHA (TL-2026-2393), also tracked as UAC-0145 ClickFix Campaign, is a critical-severity tracked intrusion set, first published 2026-07-15. It is attributed to UAC-0145 (Russia) with high confidence, affects Microsoft Windows, maps to 21 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 24 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
21MITRE ATT&CK
Actors
1UAC-0145
Detection rules
9SPL · KQL · Sigma
IOCs
24Indicators of compromise

Key facts for TL-2026-2393

Threat ID
TL-2026-2393
Also known as
UAC-0145 ClickFix Campaign, SMARTAXE Operation, COWARDDUCK Campaign
Severity
CRITICAL
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution
UAC-0145
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government administration, military, defense, telecoms, energy
Target regions
ukraine, 151 - Eastern Europe
Detection rules
9
Indicators of compromise
24

How UAC-0145 (Sandworm sub-cluster) ClickFix fake-CAPTCHA works

CERT-UA attributes active multi-vector campaign activity to UAC-0145, a sub-cluster of the GRU-linked Sandworm (APT44/Seashell Blizzard). Since June 2026, the group compromised at least 10 legitimate Ukrainian websites to serve fake CAPTCHAs that trick users into running malicious PowerShell commands (ClickFix technique), delivering a Windows malware chain (GHETTOVIBE, SCOUTCURL, FLUIDLEECH, LOADLOOP, FREAKYPOLL) and an Android backdoor (COWARDDUCK) via Signal messaging. The CAPTCHA payload resolves C2 infrastructure domains from Ethereum smart contracts via eth_call (EtherHiding), making takedown of C2 domains significantly more difficult as the resolution layer lives on an immutable blockchain.

UAC-0145 is a sub-cluster within UAC-0002/Sandworm (also tracked as APT44, Seashell Blizzard), the Russian GRU Main Intelligence Directorate's most destructive advanced persistent threat group. CERT-UA documented a marked expansion in UAC-0145's initial-access tradecraft during spring and summer 2026, identifying three concurrent vectors targeting Ukrainian military, government, and civilian infrastructure.

The primary new vector is a ClickFix fake-CAPTCHA campaign. Since June 2026, UAC-0145 compromised at least 10 legitimate Ukrainian websites, injecting them with SMARTAXE — a bespoke JavaScript tool layered on the Cloaking.House commercial traffic-filtering service. SMARTAXE dynamically alters webpage content based on visitor characteristics (IP geolocation, browser fingerprint, VPN/proxy status), serving a convincing Google-branded reCAPTCHA lookalike only to targeted Ukrainian visitors. The fake CAPTCHA instructs victims to press Windows+R, paste a clipboard-hijacked PowerShell command, and press Enter. The PowerShell one-liner downloads and saves a VBS persistence stub (GHETTOVIBE) to the Windows Startup autorun directory. GHETTOVIBE executes a PowerShell reconnaissance script (SCOUTCURL) that profiles the compromised host, collecting OS details, installed applications, files, and browser data to assess the target's value. On high-value systems, loaders FLUIDLEECH (masquerading as ESET AV Remover software) and/or LOADLOOP deploy the final-stage payload — FREAKYPOLL, a Python backdoor distributed as compiled .pyc bytecode that provides persistent remote access.

Critically, SMARTAXE's injected CAPTCHA content retrieves its remote C2 domain via EtherHiding — an Ethereum JSON-RPC eth_call to a specific smart contract address and function selector hardcoded in the script. The smart contract stores the current C2 domain on-chain, queryable by any victim's browser through public RPC nodes. Because blockchain data is immutable and replicated across thousands of independent nodes, this C2 resolution layer cannot be sinkholed, seized, or deleted. Operators rotate C2 addresses by issuing a single low-cost on-chain transaction, immediately redirecting all active infections to new infrastructure.

The second vector targets mobile devices: COWARDDUCK, a full-featured Android backdoor, is distributed as fake security/antivirus APK files via the Signal messaging app. COWARDDUCK collects device contacts, real-time geolocation, and files with specific extensions (.conf, .json, .ovpn, .txt, .doc, .docx, .xls, .xlsx, .pptx, .zip, .rar) from user directories (DCIM, Documents, Downloads, Pictures, Alarms). Exfiltration occurs via the Dropbox cloud API, while C2 tasking is retrieved through content hosted on legitimate services including Steam Community, proxied through DuckDuckGo's public proxy to blend into normal traffic.

The third continuing vector involves trojanized software installers (Windows, Microsoft Office) distributed via torrent trackers, carrying embedded backdoors. At least one infection chain from this vector led to lateral movement using OpenSSH and Tor (exposing local ports 445, 3389, and 22), data exfiltration via rsync, and culminated in a destructive cyberattack against the infrastructure of a Ukrainian central executive authority.

This campaign marks a significant tactical departure for Sandworm, which previously relied primarily on trojanized software installers and bogus antivirus distributions through messaging apps. The adoption of ClickFix social engineering combined with blockchain-based C2 resolution (EtherHiding) represents a sophisticated evolution in initial-access tradecraft for a state-sponsored APT group. The integration of both Windows and Android targeting in a single concurrent campaign also demonstrates broadening operational scope.

MITRE ATT&CK techniques used in TL-2026-2393

Collection

T1005 Data from Local System; T1119 Automated Collection

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1218 System Binary Proxy Execution

Exfiltration

T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1568 Dynamic Resolution; T1572 Protocol Tunneling

Discovery

T1082 System Information Discovery

Initial Access

T1195 Supply Chain Compromise; T1566 Phishing

Impact

T1485 Data Destruction; T1490 Inhibit System Recovery

Persistence

T1547 Boot or Logon Autostart Execution

Credential Access

T1555 Credentials from Password Stores

Affected products and versions in UAC-0145 (Sandworm sub-cluster) ClickFix fake-CAPTCHA

  • Microsoft — Windows
    Vulnerable versions: 10; 11; Server 2019; Server 2022
  • Google — Android
    Vulnerable versions: Multiple versions
  • WordPress — CMS (compromised instances)
    Vulnerable versions: Multiple versions
  • Dropbox — API (abused legitimate service)
  • Signal — Messenger (abused delivery channel)

Remediation for UAC-0145 (Sandworm sub-cluster) ClickFix fake-CAPTCHA

Immediate actions

  • Block known C2 domains at network perimeter: update-requirements[.]com, entouchnetworks[.]com, static[.]diagnostics-monitoring[.]com, static[.]opennetworkconnect[.]com, softupdater[.]org, soft[.]softchecker[.]org, pack[.]softpacker[.]org, smartlinkupload[.]com, delta[.]smartlinkupload[.]com, offlce366[.]com, 365softupdate[.]com
  • Scan all endpoints for VBS files in Startup folder, particularly Copilot Agent.vbs and Work Copilot.vbs
  • Check for Python bytecode (update.cpython-314.pyc) in %LOCALAPPDATA%\SystemHelper\python\
  • Investigate web servers for unauthorized JavaScript, specifically wp-header.js and any eth_call RPC calls
  • Review PowerShell execution logs for unusual browser-to-PowerShell process chains

Workarounds

  • Conduct user awareness training specifically focused on fake CAPTCHA/ClickFix social engineering techniques
  • Restrict PowerShell execution for non-administrative users via Windows AppLocker or WDAC policies where operationally feasible
  • Block outbound JSON-RPC calls to public Ethereum RPC nodes from non-Web3 developer workstations
  • Enforce application control measures for Python bytecode execution in user-writable directories

Longer-term hardening

  • Deploy EDR with behavioral detection rules for the browser-to-PowerShell-to-VBS process chain (Sysmon EID 1/EDR parent-child tracking)
  • Monitor for eth_call JSON-RPC traffic to public Ethereum RPC endpoints from non-Web3 development endpoints
  • Implement Android sideloading restrictions on BYOD devices and monitor for unusual Dropbox API + Steam Community C2 patterns
  • Deploy website integrity monitoring (CMS file hash verification, unauthorized script injection detection) for public-facing WordPress sites
  • Establish threat-hunting queries for EtherHiding dead-drop resolver patterns across the environment

Timeline of UAC-0145 (Sandworm sub-cluster) ClickFix fake-CAPTCHA

  • UAC-0145 registers malicious domains and deploys Ethereum smart contracts for EtherHiding C2 resolution infrastructure, establishing blockchain-based dead-drop resolvers for the campaign.
  • UAC-0145 begins compromising legitimate Ukrainian websites, injecting SMARTAXE JavaScript and configuring Cloaking.House traffic filtering to serve fake CAPTCHA overlays to targeted visitors.
  • First ClickFix fake-CAPTCHA attacks observed in the wild against Ukrainian targets. Victims are tricked into running PowerShell commands that deliver GHETTOVIBE VBS persistence stub followed by SCOUTCURL reconnaissance script.
  • COWARDDUCK Android backdoor first distributed via Signal messaging app, disguised as ESET antivirus/security APK files. Targets Ukrainian military personnel through social engineering on messaging platforms.
  • UAC-0145 infrastructure reaches peak operational scale with at least 10 compromised Ukrainian websites actively serving SMARTAXE-injected fake CAPTCHAs. FLUIDLEECH, LOADLOOP loaders and FREAKYPOLL Python backdoor deployed on high-value targets.
  • At least one infection chain originating from torrent-based trojanized software installers leads to lateral movement via OpenSSH and Tor, data exfiltration via rsync, and a destructive cyberattack against the infrastructure of a Ukrainian central executive authority.
  • CERT-UA publishes advisory #6318437 detailing the UAC-0145 campaign, documenting all three initial-access vectors (ClickFix, torrent trojanized installers, Signal APK delivery) and the full malware toolchain including EtherHiding technique.
  • The Hacker News and other security outlets publish public coverage of the UAC-0145 campaign, bringing broader awareness to the ClickFix + EtherHiding technique combination being deployed by a GRU-linked APT group.
  • Campaign remains active. Security researchers and threat intelligence platforms (CTIPilot, Threat.wiki, CraftedSignal) publish detailed technical analyses with full IOCs, behavioral detection guidance, and defensive recommendations.

Sources cited for UAC-0145 (Sandworm sub-cluster) ClickFix fake-CAPTCHA

Detection coverage for TL-2026-2393

As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2393 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
24 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats