← Back to blog

Russian Hackers Use Fake CAPTCHAs to Target Ukrainian Devices

UAC-0145 deploys ClickFix CAPTCHA lures to deliver malware to Ukrainian systems. The campaign exploits user trust in familiar security prompts.

TL;DR

  • UAC-0145, a Sandworm-linked group, uses fake CAPTCHAs to deploy malware.
  • Targets are tricked into clicking malicious elements disguised as security checks.
  • Campaign specifically affects Ukrainian devices and networks.
  • CERT-UA attributes the activity to GRU-affiliated Russian threat actors.
  • Organizations should verify CAPTCHA sources and educate users on social engineering.

Cyber threat actors linked to Russia have launched a new campaign targeting Ukrainian systems using a technique known as ClickFix. This method involves overlaying fake CAPTCHA prompts on websites to trick users into executing malicious actions. Once engaged, victims unknowingly install data-stealing malware onto their devices.

The Computer Emergency Response Team of Ukraine (CERT-UA) has attributed this activity to UAC-0145, a subgroup of the notorious Sandworm hacking unit. Sandworm is widely recognized as part of the GRU, Russia’s military intelligence agency. This latest operation demonstrates how adversaries continue to exploit human psychology and trusted interface elements to bypass technical defenses.

How the Attack Works

  • Attackers inject fake CAPTCHA overlays into compromised or spoofed websites.
  • Users are prompted to click what appears to be a standard security check.
  • Interaction triggers the download or execution of malware payloads.
  • The tactic relies on user familiarity and trust in common web security UI.

Defensive Recommendations

  • Verify the legitimacy of CAPTCHA prompts, especially on sensitive sites.
  • Implement content security policies (CSP) to prevent unauthorized script injection.
  • Monitor network traffic for unusual outbound connections post-user interaction.
  • Train staff to recognize social engineering tactics that mimic legitimate UI patterns.
  • Use endpoint detection and response tools to identify suspicious file executions.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Russian Hackers Use Fake CAPTCHAs to Target Ukrainian Devices — Agent Breach Blog | Agent Breach