Essential Insights
- Russian state-sponsored hackers (UAC-0145/Sandworm) are using fake CAPTCHA checks and web cloaking techniques, including EtherHiding and SMARTAXE, to deliver data-stealing malware and RATs via compromised websites.
- The threat actors employ PowerShell scripts like SCOUTCURL, along with loaders such as FLUIDLEECH and LOADLOOP, to infect endpoints and gather reconnaissance data on compromised machines.
- They also distribute malicious Android APK files disguised as security tools containing the COWARDDUCK backdoor, which exfiltrates sensitive data and geolocation info via cloud services and external servers.
Threat Overview, Attack Techniques, and Targets
Russian state-sponsored threat actors, specifically UAC-0145 linked to Sandworm and GRU, are using ClickFix CAPTCHAs to infect Ukrainian devices. They set up fake CAPTCHA checks on compromised websites that trick users into executing malicious PowerShell commands. These commands can download and save malware, such as the GHETTOVIBE VBS file, to the device’s startup folder.
The attackers also use a PowerShell script called SCOUTCURL to gather information about infected machines. They distribute malware like FLUIDLEECH and LOADLOOP as loaders, and FREAKYPOLL as a backdoor. Additionally, they target mobile devices by disguising malicious APK files as security tools, which install the COWARDDUCK backdoor. This malware can steal contacts, certain files, and real-time location data, then upload it using Dropbox or retrieve commands from external sources.
Between June and July 2026, at least 10 websites were compromised. The attackers used tools like Cloaking.House and SMARTAXE to serve customized web pages and CAPTCHAs. They also employed EtherHiding techniques involving Ethereum smart contracts to hide the infection process. Their targets primarily include Ukrainian devices, both desktop and mobile.
Impact, Security Implications, and Remediation Guidance
The campaign can lead to significant damage. Infected devices may have sensitive data stolen, including personal contacts, files, and location data. Mobile malware, such as COWARDDUCK, can also secretly collect information and exfiltrate it. This increases the risk of data breaches and further cyber espionage.
The use of ClickFix CAPTCHAs shows how social engineering can successfully distribute malware. The techniques they employ make detection more difficult. These practices highlight the importance of strong security measures on web services and user devices.
For remediation, it is recommended to consult with the relevant vendor or cybersecurity authority. They can provide specific guidance on removing malware and strengthening defenses. It is crucial to update software, disable scripts from untrusted sources, and monitor network traffic for suspicious activities.
Discover More Technology Insights
Explore the future of technology with our detailed insights on Artificial Intelligence.
Access comprehensive resources on technology by visiting Wikipedia.
ThreatIntel-V1
