CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 2801

As cited

Citation snapshot as of .

threat intel

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

UAC-0145, a sub-cluster of the Russian state-sponsored Sandworm group, has been conducting a campaign against Ukrainian targets using ClickFix CAPTCHAs to lure victims into installing data-stealing malware. The Computer Emergency Response Team of Ukraine (CERT-UA) detected and attributed the activity, which exploits a social engineering technique to trick users into compromising their own devices.

Why it matters: Ukrainian organizations and individuals face targeted infection campaigns from a Russian state actor; practitioners should educate users on ClickFix threats and enforce controls to block unauthorized malware installation.

Source published
First seen by Cybersecurity Tracker

Source attribution