As cited
Citation snapshot as of .
threat intel
Now, even Russia's most elite hackers are using Clickfix to infect devices
Sandworm, an elite hacking unit within Russia's GRU military intelligence, has adopted the Clickfix technique to target sensitive organizations in Ukraine. Clickfix tricks users into copying and pasting malicious commands into a terminal by masking them as CAPTCHA verification steps, leading to malware installation or data theft. Ukrainian authorities discovered at least 10 compromised websites using this method, with confirmed infections from FreakyPoll, a custom Sandworm malware package.
Why it matters: Organizations in Ukraine and those handling sensitive data are at immediate risk from state-sponsored attacks using a low-friction social engineering technique; security teams should educate users to never paste unknown commands into terminals and monitor for Clickfix lures.
- Source published
- First seen by Cybersecurity Tracker