🟠 High | Source: The Hacker News
Russian state-sponsored group UAC-0145, a sub-cluster of the GRU-linked Sandworm unit, is using fake CAPTCHA prompts (the ‘ClickFix’ technique) to trick Ukrainian users into manually executing malware on their own machines. The attack results in data-stealing malware being installed without requiring any traditional exploit. This matters because the social engineering approach bypasses many technical controls by making the victim an unwitting participant in their own compromise.
Security Architect’s Take: Enforce application whitelisting and restrict PowerShell/script execution via Group Policy or endpoint controls to prevent ClickFix-style attacks where users paste and run malicious commands. Ensure user awareness training covers fake CAPTCHA and clipboard-injection lures, particularly for any staff or contractors with exposure to Ukrainian government or defence-adjacent supply chains.
Original advisory: UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware