CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

Now, even Russia's most elite hackers are using Clickfix to infect devices

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 2731

As cited

Citation snapshot as of .

threat intel

Now, even Russia's most elite hackers are using Clickfix to infect devices

Sandworm, an elite hacking unit within Russia's GRU military intelligence, has adopted the Clickfix technique to target sensitive organizations in Ukraine. Clickfix tricks users into copying and pasting malicious commands into a terminal by masking them as CAPTCHA verification steps, leading to malware installation or data theft. Ukrainian authorities discovered at least 10 compromised websites using this method, with confirmed infections from FreakyPoll, a custom Sandworm malware package.

Why it matters: Organizations in Ukraine and those handling sensitive data are at immediate risk from state-sponsored attacks using a low-friction social engineering technique; security teams should educate users to never paste unknown commands into terminals and monitor for Clickfix lures.

Source published
First seen by Cybersecurity Tracker

Source attribution