UAC-0145 Hackers Use ClickFix Technique and Fake Applications to Target Users in Ukraine

Views: 94 views

394/69 Monday, July 20, 2026

The Computer Emergency Response Team of Ukraine (CERT-UA) has detected a cyberattack operation by the threat group UAC-0145, a subgroup within the Sandworm network linked to Russian intelligence services. In this campaign, the hackers shifted their tactics from using fake installers to deceiving users through the ClickFix technique on compromised websites, combined with malware distribution through messaging applications. The attackers trick victims into manually installing malicious files, putting sensitive data on both Windows and Android devices at risk of theft.

Analysis found that the browser-based attack uses fake verification or CAPTCHA windows to trick users into copying PowerShell commands and running them in their own terminals. The attackers used the SMARTAXE tool together with the EtherHiding technique to retrieve malicious domain information from Ethereum smart contracts and dynamically change webpage content based on the visitor’s profile. This led to the download of multiple malware families, including GHETTOVIBE, FLUIDLEECH, and FREAKYPOLL, which are used for espionage and system control. In addition, the attackers impersonated a security support account named Delta_security to create fear that the victim’s account would be suspended. They then sent links and APK files, such as fake ESET.apk or ESET Smart Security installers, to deceive victims. Installing these fake applications results in the deployment of COWARDDUCK malware on Android devices, allowing attackers to access contacts, location data, and important documents on the device before exfiltrating them to command-and-control servers through the Dropbox cloud service API.

To prevent and reduce the risk from this threat, experts advise users to exercise caution when browsing websites and never copy commands from webpages to run on their systems, especially when instructed by fake CAPTCHA prompts. Users should also avoid downloading and installing APK files from chat messages or suspicious links sent by others and should install applications only from official app stores. For organizational administrators, PowerShell execution on user devices should be reviewed and restricted where appropriate. Administrators should also monitor abnormal connections to external public cloud services and closely track communications with suspicious domains or destinations.

Source: https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html