A recent wave of cyberattacks has targeted Ukrainian devices, with Russian state-sponsored threat actors employing a deceptive technique known as ClickFix. This method involves the use of counterfeit CAPTCHA checks to lure users into executing harmful commands on their systems. The Computer Emergency Response Team of Ukraine, CERT-UA, has linked this activity to UAC-0145, a subgroup within the Sandworm hacking unit, which operates under Russia's GRU intelligence agency.

Victims of these attacks are tricked into running a PowerShell command that downloads and saves a VBS file to their startup directory. One such program, named GHETTOVIBE, is part of the malware arsenal used in this operation. Additionally, the attackers deploy a PowerShell script called SCOUTCURL, which collects reconnaissance data from infected machines. The campaign has compromised at least ten websites, utilizing the Cloaking.House service to serve malicious content selectively.

The attackers also employ a custom tool named SMARTAXE to modify webpage content dynamically, injecting CAPTCHA checks designed to retrieve domain names from Ethereum smart contracts. Furthermore, CERT-UA discovered that UAC-0145 uses additional techniques, such as distributing tampered APK files disguised as security tools via messaging apps. These APK files contain a backdoor known as COWARDDUCK, capable of collecting sensitive information and communicating with remote servers through the Dropbox API and other legitimate sites.

This campaign marks a shift from previous tactics that involved trojanized installers or fake antivirus software. The ongoing use of ClickFix underscores its effectiveness as a social engineering tool in delivering various types of malware, including OXLOADER and SCMBANKER.