# UAC-0145 (Sandworm sub-cluster) ClickFix fake-CAPTCHA campaign against Ukrainian devices with EtherHiding C2 resolution

> CERT-UA attributes active multi-vector campaign activity to UAC-0145, a sub-cluster of the GRU-linked Sandworm (APT44/Seashell Blizzard). Since June 2026, the group compromised at least 10 legitimate Ukrainian websites to serve fake CAPTCHAs that trick users into running malicious PowerShell commands (ClickFix technique), delivering a Windows malware chain (GHETTOVIBE, SCOUTCURL, FLUIDLEECH, LOADLOOP, FREAKYPOLL) and an Android backdoor (COWARDDUCK) via Signal messaging. The CAPTCHA payload resolves C2 infrastructure domains from Ethereum smart contracts via eth_call (EtherHiding), making takedown of C2 domains significantly more difficult as the resolution layer lives on an immutable blockchain.

- **Published:** 2026-07-15T00:00:00Z
- **Last reviewed:** 2026-07-15T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2393
- **ID:** TL-2026-2393
- **Severity:** CRITICAL
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Actor:** UAC-0145 (Russia)
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

UAC-0145 is a sub-cluster within UAC-0002/Sandworm (also tracked as APT44, Seashell Blizzard), the Russian GRU Main Intelligence Directorate's most destructive advanced persistent threat group. CERT-UA documented a marked expansion in UAC-0145's initial-access tradecraft during spring and summer 2026, identifying three concurrent vectors targeting Ukrainian military, government, and civilian infrastructure.

The primary new vector is a ClickFix fake-CAPTCHA campaign. Since June 2026, UAC-0145 compromised at least 10 legitimate Ukrainian websites, injecting them with SMARTAXE — a bespoke JavaScript tool layered on the Cloaking.House commercial traffic-filtering service. SMARTAXE dynamically alters webpage content based on visitor characteristics (IP geolocation, browser fingerprint, VPN/proxy status), serving a convincing Google-branded reCAPTCHA lookalike only to targeted Ukrainian visitors. The fake CAPTCHA instructs victims to press Windows+R, paste a clipboard-hijacked PowerShell command, and press Enter. The PowerShell one-liner downloads and saves a VBS persistence stub (GHETTOVIBE) to the Windows Startup autorun directory. GHETTOVIBE executes a PowerShell reconnaissance script (SCOUTCURL) that profiles the compromised host, collecting OS details, installed applications, files, and browser data to assess the target's value. On high-value systems, loaders FLUIDLEECH (masquerading as ESET AV Remover software) and/or LOADLOOP deploy the final-stage payload — FREAKYPOLL, a Python backdoor distributed as compiled .pyc bytecode that provides persistent remote access.

Critically, SMARTAXE's injected CAPTCHA content retrieves its remote C2 domain via EtherHiding — an Ethereum JSON-RPC eth_call to a specific smart contract address and function selector hardcoded in the script. The smart contract stores the current C2 domain on-chain, queryable by any victim's browser through public RPC nodes. Because blockchain data is immutable and replicated across thousands of independent nodes, this C2 resolution layer cannot be sinkholed, seized, or deleted. Operators rotate C2 addresses by issuing a single low-cost on-chain transaction, immediately redirecting all active infections to new infrastructure.

The second vector targets mobile devices: COWARDDUCK, a full-featured Android backdoor, is distributed as fake security/antivirus APK files via the Signal messaging app. COWARDDUCK collects device contacts, real-time geolocation, and files with specific extensions (.conf, .json, .ovpn, .txt, .doc, .docx, .xls, .xlsx, .pptx, .zip, .rar) from user directories (DCIM, Documents, Downloads, Pictures, Alarms). Exfiltration occurs via the Dropbox cloud API, while C2 tasking is retrieved through content hosted on legitimate services including Steam Community, proxied through DuckDuckGo's public proxy to blend into normal traffic.

The third continuing vector involves trojanized software installers (Windows, Microsoft Office) distributed via torrent trackers, carrying embedded backdoors. At least one infection chain from this vector led to lateral movement using OpenSSH and Tor (exposing local ports 445, 3389, and 22), data exfiltration via rsync, and culminated in a destructive cyberattack against the infrastructure of a Ukrainian central executive authority.

This campaign marks a significant tactical departure for Sandworm, which previously relied primarily on trojanized software installers and bogus antivirus distributions through messaging apps. The adoption of ClickFix social engineering combined with blockchain-based C2 resolution (EtherHiding) represents a sophisticated evolution in initial-access tradecraft for a state-sponsored APT group. The integration of both Windows and Android targeting in a single concurrent campaign also demonstrates broadening operational scope.

## MITRE ATT&CK

- T1566 Phishing
- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1547 Boot or Logon Autostart Execution
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1218 System Binary Proxy Execution
- T1555 Credentials from Password Stores
- T1082 System Information Discovery
- T1021 Remote Services
- T1071 Application Layer Protocol
- T1572 Protocol Tunneling
- T1090 Proxy
- T1568 Dynamic Resolution
- T1005 Data from Local System
- T1119 Automated Collection
- T1567 Exfiltration Over Web Service
- T1048 Exfiltration Over Alternative Protocol
- T1485 Data Destruction
- T1490 Inhibit System Recovery

## Sources

- [CERT-UA: Primary compromise vectors used by UAC-0145 as of July 2026](https://cert.gov.ua/article/6318437)
- [UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware](https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html)
- [CTIPilot: UAC-0145 Sandworm ClickFix EtherHiding Android Backdoor](https://ctipilot.ch/entries/2026-07-20/uac-0145-sandworm-clickfix-etherhiding-android-backdoor/)
- [Threat.wiki: UAC-0145 ClickFix SMARTAXE COWARDDUCK Campaign Analysis](https://threat.wiki/ops/uac-0145-clickfix-smartaxe-cowardduck/)
- [Trend Micro: Smart Contracts for Command and Control — EtherHiding Technical Analysis](https://www.trendmicro.com/en/research/26/e/smart-contracts-for-command-and-control.html)
- [Dark Reading: ClickFix Campaign Compromises 31 Organizations, Abuses Polygon Blockchain](https://www.darkreading.com/endpoint-security/clickfix-campaign-comprises-31-orgs-abuses-polygon-blockchain)
- [Hexnode Blog: ClickFix Malware — UAC-0145 Sandworm Campaign Analysis](https://www.hexnode.com/blogs/clickfix-malware-uac-0145-sandworm/)
- [CraftedSignal Threat Feed: July 2026 UAC-0145 ClickFix CAPTCHA Campaign](https://feed.craftedsignal.io/briefs/2026-07-uac-0145-clickfix-captchas/)
- [eSentire: EtherRAT — Node.js RAT Using EtherHiding on Ethereum](https://www.esentire.com/blog/etherrat-node-js-rat)
- [Guardz Research: EtherHiding Technique First Documentation (October 2023)](https://www.guardz.com/blog/etherhiding-blockchain-malware-c2)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2393
