Threat reportThreat IntelligenceTL-2026-2393
UAC-0145 (Sandworm sub-cluster) ClickFix fake-CAPTCHA campaign against Ukrainian devices with EtherHiding C2 resolution
UAC-0145 (Sandworm sub-cluster) ClickFix fake-CAPTCHA (TL-2026-2393), also tracked as UAC-0145 ClickFix Campaign, is a critical-severity tracked intrusion set, first published 2026-07-15. It is attributed to UAC-0145 (Russia) with high confidence, affects Microsoft Windows, maps to 21 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 21MITRE ATT&CK
- Actors
- 1UAC-0145
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-2393
- Threat ID
- TL-2026-2393
- Also known as
- UAC-0145 ClickFix Campaign, SMARTAXE Operation, COWARDDUCK Campaign
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution
- UAC-0145
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government administration, military, defense, telecoms, energy
- Target regions
- ukraine, 151 - Eastern Europe
- Detection rules
- 9
- Indicators of compromise
- 24
How UAC-0145 (Sandworm sub-cluster) ClickFix fake-CAPTCHA works
CERT-UA attributes active multi-vector campaign activity to UAC-0145, a sub-cluster of the GRU-linked Sandworm (APT44/Seashell Blizzard). Since June 2026, the group compromised at least 10 legitimate Ukrainian websites to serve fake CAPTCHAs that trick users into running malicious PowerShell commands (ClickFix technique), delivering a Windows malware chain (GHETTOVIBE, SCOUTCURL, FLUIDLEECH, LOADLOOP, FREAKYPOLL) and an Android backdoor (COWARDDUCK) via Signal messaging. The CAPTCHA payload resolves C2 infrastructure domains from Ethereum smart contracts via eth_call (EtherHiding), making takedown of C2 domains significantly more difficult as the resolution layer lives on an immutable blockchain.
UAC-0145 is a sub-cluster within UAC-0002/Sandworm (also tracked as APT44, Seashell Blizzard), the Russian GRU Main Intelligence Directorate's most destructive advanced persistent threat group. CERT-UA documented a marked expansion in UAC-0145's initial-access tradecraft during spring and summer 2026, identifying three concurrent vectors targeting Ukrainian military, government, and civilian infrastructure.
The primary new vector is a ClickFix fake-CAPTCHA campaign. Since June 2026, UAC-0145 compromised at least 10 legitimate Ukrainian websites, injecting them with SMARTAXE — a bespoke JavaScript tool layered on the Cloaking.House commercial traffic-filtering service. SMARTAXE dynamically alters webpage content based on visitor characteristics (IP geolocation, browser fingerprint, VPN/proxy status), serving a convincing Google-branded reCAPTCHA lookalike only to targeted Ukrainian visitors. The fake CAPTCHA instructs victims to press Windows+R, paste a clipboard-hijacked PowerShell command, and press Enter. The PowerShell one-liner downloads and saves a VBS persistence stub (GHETTOVIBE) to the Windows Startup autorun directory. GHETTOVIBE executes a PowerShell reconnaissance script (SCOUTCURL) that profiles the compromised host, collecting OS details, installed applications, files, and browser data to assess the target's value. On high-value systems, loaders FLUIDLEECH (masquerading as ESET AV Remover software) and/or LOADLOOP deploy the final-stage payload — FREAKYPOLL, a Python backdoor distributed as compiled .pyc bytecode that provides persistent remote access.
Critically, SMARTAXE's injected CAPTCHA content retrieves its remote C2 domain via EtherHiding — an Ethereum JSON-RPC eth_call to a specific smart contract address and function selector hardcoded in the script. The smart contract stores the current C2 domain on-chain, queryable by any victim's browser through public RPC nodes. Because blockchain data is immutable and replicated across thousands of independent nodes, this C2 resolution layer cannot be sinkholed, seized, or deleted. Operators rotate C2 addresses by issuing a single low-cost on-chain transaction, immediately redirecting all active infections to new infrastructure.
The second vector targets mobile devices: COWARDDUCK, a full-featured Android backdoor, is distributed as fake security/antivirus APK files via the Signal messaging app. COWARDDUCK collects device contacts, real-time geolocation, and files with specific extensions (.conf, .json, .ovpn, .txt, .doc, .docx, .xls, .xlsx, .pptx, .zip, .rar) from user directories (DCIM, Documents, Downloads, Pictures, Alarms). Exfiltration occurs via the Dropbox cloud API, while C2 tasking is retrieved through content hosted on legitimate services including Steam Community, proxied through DuckDuckGo's public proxy to blend into normal traffic.
The third continuing vector involves trojanized software installers (Windows, Microsoft Office) distributed via torrent trackers, carrying embedded backdoors. At least one infection chain from this vector led to lateral movement using OpenSSH and Tor (exposing local ports 445, 3389, and 22), data exfiltration via rsync, and culminated in a destructive cyberattack against the infrastructure of a Ukrainian central executive authority.
This campaign marks a significant tactical departure for Sandworm, which previously relied primarily on trojanized software installers and bogus antivirus distributions through messaging apps. The adoption of ClickFix social engineering combined with blockchain-based C2 resolution (EtherHiding) represents a sophisticated evolution in initial-access tradecraft for a state-sponsored APT group. The integration of both Windows and Android targeting in a single concurrent campaign also demonstrates broadening operational scope.
MITRE ATT&CK techniques used in TL-2026-2393
Collection
T1005 Data from Local System; T1119 Automated Collection
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1218 System Binary Proxy Execution
Exfiltration
T1048 Exfiltration Over Alternative Protocol; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1568 Dynamic Resolution; T1572 Protocol Tunneling
Discovery
T1082 System Information Discovery
Initial Access
T1195 Supply Chain Compromise; T1566 Phishing
Impact
T1485 Data Destruction; T1490 Inhibit System Recovery
Persistence
T1547 Boot or Logon Autostart Execution
Credential Access
Affected products and versions in UAC-0145 (Sandworm sub-cluster) ClickFix fake-CAPTCHA
Remediation for UAC-0145 (Sandworm sub-cluster) ClickFix fake-CAPTCHA
Immediate actions
- Block known C2 domains at network perimeter: update-requirements[.]com, entouchnetworks[.]com, static[.]diagnostics-monitoring[.]com, static[.]opennetworkconnect[.]com, softupdater[.]org, soft[.]softchecker[.]org, pack[.]softpacker[.]org, smartlinkupload[.]com, delta[.]smartlinkupload[.]com, offlce366[.]com, 365softupdate[.]com
- Scan all endpoints for VBS files in Startup folder, particularly Copilot Agent.vbs and Work Copilot.vbs
- Check for Python bytecode (update.cpython-314.pyc) in %LOCALAPPDATA%\SystemHelper\python\
- Investigate web servers for unauthorized JavaScript, specifically wp-header.js and any eth_call RPC calls
- Review PowerShell execution logs for unusual browser-to-PowerShell process chains
Workarounds
- Conduct user awareness training specifically focused on fake CAPTCHA/ClickFix social engineering techniques
- Restrict PowerShell execution for non-administrative users via Windows AppLocker or WDAC policies where operationally feasible
- Block outbound JSON-RPC calls to public Ethereum RPC nodes from non-Web3 developer workstations
- Enforce application control measures for Python bytecode execution in user-writable directories
Longer-term hardening
- Deploy EDR with behavioral detection rules for the browser-to-PowerShell-to-VBS process chain (Sysmon EID 1/EDR parent-child tracking)
- Monitor for eth_call JSON-RPC traffic to public Ethereum RPC endpoints from non-Web3 development endpoints
- Implement Android sideloading restrictions on BYOD devices and monitor for unusual Dropbox API + Steam Community C2 patterns
- Deploy website integrity monitoring (CMS file hash verification, unauthorized script injection detection) for public-facing WordPress sites
- Establish threat-hunting queries for EtherHiding dead-drop resolver patterns across the environment
Timeline of UAC-0145 (Sandworm sub-cluster) ClickFix fake-CAPTCHA
- UAC-0145 registers malicious domains and deploys Ethereum smart contracts for EtherHiding C2 resolution infrastructure, establishing blockchain-based dead-drop resolvers for the campaign.
- UAC-0145 begins compromising legitimate Ukrainian websites, injecting SMARTAXE JavaScript and configuring Cloaking.House traffic filtering to serve fake CAPTCHA overlays to targeted visitors.
- First ClickFix fake-CAPTCHA attacks observed in the wild against Ukrainian targets. Victims are tricked into running PowerShell commands that deliver GHETTOVIBE VBS persistence stub followed by SCOUTCURL reconnaissance script.
- COWARDDUCK Android backdoor first distributed via Signal messaging app, disguised as ESET antivirus/security APK files. Targets Ukrainian military personnel through social engineering on messaging platforms.
- UAC-0145 infrastructure reaches peak operational scale with at least 10 compromised Ukrainian websites actively serving SMARTAXE-injected fake CAPTCHAs. FLUIDLEECH, LOADLOOP loaders and FREAKYPOLL Python backdoor deployed on high-value targets.
- At least one infection chain originating from torrent-based trojanized software installers leads to lateral movement via OpenSSH and Tor, data exfiltration via rsync, and a destructive cyberattack against the infrastructure of a Ukrainian central executive authority.
- CERT-UA publishes advisory #6318437 detailing the UAC-0145 campaign, documenting all three initial-access vectors (ClickFix, torrent trojanized installers, Signal APK delivery) and the full malware toolchain including EtherHiding technique.
- The Hacker News and other security outlets publish public coverage of the UAC-0145 campaign, bringing broader awareness to the ClickFix + EtherHiding technique combination being deployed by a GRU-linked APT group.
- Campaign remains active. Security researchers and threat intelligence platforms (CTIPilot, Threat.wiki, CraftedSignal) publish detailed technical analyses with full IOCs, behavioral detection guidance, and defensive recommendations.
Sources cited for UAC-0145 (Sandworm sub-cluster) ClickFix fake-CAPTCHA
- CERT-UA: Primary compromise vectors used by UAC-0145 as of July 2026
- UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware
- CTIPilot: UAC-0145 Sandworm ClickFix EtherHiding Android Backdoor
- Threat.wiki: UAC-0145 ClickFix SMARTAXE COWARDDUCK Campaign Analysis
- Trend Micro: Smart Contracts for Command and Control — EtherHiding Technical Analysis
- Dark Reading: ClickFix Campaign Compromises 31 Organizations, Abuses Polygon Blockchain
- Hexnode Blog: ClickFix Malware — UAC-0145 Sandworm Campaign Analysis
- CraftedSignal Threat Feed: July 2026 UAC-0145 ClickFix CAPTCHA Campaign
- eSentire: EtherRAT — Node.js RAT Using EtherHiding on Ethereum
- Guardz Research: EtherHiding Technique First Documentation (October 2023)
- CISA Known Exploited Vulnerabilities Catalog
Detection coverage for TL-2026-2393
As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2393 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.