In a significant escalation of cyber warfare, Russian state-sponsored threat actors, identified as a sub-cluster of the notorious Sandworm hacking unit, have been observed leveraging the "ClickFix" strategy to compromise Ukrainian targets, infecting their systems with advanced data-stealing malware. The Computer Emergency Response Team of Ukraine (CERT-UA) issued a detailed alert on July 19, 2026, attributing this activity to UAC-0145, a segment of the Sandworm group known for its affiliation with Russia’s primary foreign military intelligence agency, the GRU. This campaign represents a new frontier in the ongoing digital conflict, showcasing an evolving array of tactics designed to trick unsuspecting users into self-infecting their machines and mobile devices.
The core of the latest attack vector hinges on the infamous ClickFix strategy, a social engineering technique that manipulates users into executing malicious commands. Threat actors are deploying fake CAPTCHA checks on compromised websites, instructing prospective Ukrainian targets to run a specific PowerShell command directly in their terminal. This seemingly innocuous step, presented as a verification measure, is in reality a sophisticated trap designed to initiate the infection chain. CERT-UA explicitly warned that this command is engineered to download and save a malicious VBS file, one variant of which has been codenamed "GHETTOVIBE," into the system’s Startup autorun directory, ensuring persistence across reboots.
Beyond GHETTOVIBE, the campaign incorporates SCOUTCURL, a PowerShell script meticulously crafted for initial reconnaissance. Upon execution, SCOUTCURL systematically harvests crucial details about the infected machine, providing the attackers with a comprehensive overview of the target environment. This preliminary data collection is vital for subsequent stages of the attack, allowing the threat actors to tailor further malicious payloads or exfiltration strategies. The sophistication of this reconnaissance phase underscores the strategic planning inherent in state-sponsored cyber operations, aiming to maximize impact and minimize detection.

The breadth of this ClickFix campaign is alarming, with CERT-UA assessing that at least ten websites were compromised between June and July 2026 as part of this operation. To effectively target specific victims and evade detection, the attackers have ingeniously employed several advanced techniques. One such method involves leveraging "Cloaking.House," a traffic filtering service that enables them to serve different content to different visitors based on various parameters. This ensures that only intended targets, likely identified by their geographical location or IP address, are presented with the malicious CAPTCHA prompts, thereby reducing the chances of security researchers or general users stumbling upon the illicit activity.
Further enhancing their operational stealth, the threat actors developed a bespoke tool named "SMARTAXE." This specialized utility dynamically alters the content of a webpage based on the site visitor’s profile, specifically to display the deceptive CAPTCHA check. The CAPTCHA content itself utilizes the "EtherHiding" technique, an innovative method to retrieve the domain name of the remote resource from an Ethereum smart contract. This decentralised approach, where the command-and-control infrastructure is obscured within a blockchain, makes it significantly harder for conventional network security tools to identify and block the communication channels used by the malware, representing a new frontier in stealthy C2 operations. This intricate web of technologies highlights a concerted effort to bypass traditional security measures and ensure high success rates for the initial infection.
The sophistication of UAC-0145’s tactics extends beyond desktop systems to mobile platforms, specifically targeting Android devices. CERT-UA has also uncovered evidence of the threat actor distributing malicious APK (Android Application Package) files via popular messaging applications. These APKs are cleverly disguised as legitimate security tools, preying on users’ inherent need for digital protection. Once installed, the embedded malware, a full-featured backdoor codenamed "COWARDDUCK," grants the attackers extensive control over the compromised device. COWARDDUCK is designed to clandestinely collect a wide array of sensitive information, including but not limited to:
- Contact lists and call logs: Accessing the user’s social network and communication history.
- SMS messages: Intercepting two-factor authentication codes and private conversations.
- Geolocation data: Tracking the device’s real-time physical location.
- Installed applications: Inventorying software to identify potential vulnerabilities or sensitive apps.
- Device information: Gathering hardware and software specifics for profiling.
- Microphone recordings: Covertly listening to surrounding audio.
- Camera access: Capturing photos or videos without user consent.
- Files stored on the device: Exfiltrating documents, images, and other personal data.
For data exfiltration and command retrieval, COWARDDUCK leverages legitimate cloud services and websites to blend in with normal network traffic. Specifically, the malware utilizes the Dropbox cloud service API to upload collected files, while retrieving commands or additional data from external servers or seemingly innocuous sites like steamcommunity[.]com. This strategy of "living off the land" by abusing trusted platforms further complicates detection and attribution, as the malicious traffic appears to be legitimate usage of widely accepted services.

This current campaign, featuring ClickFix and COWARDDUCK, marks a noticeable strategic shift for the Kremlin-backed hacking crew. In previous operations, Sandworm and its sub-groups were more frequently observed deploying trojanized installers for Microsoft Windows or Office, which contained built-in backdoors, or distributing bogus antivirus software through messaging apps like Signal. The transition to the ClickFix strategy, with its emphasis on user-executed PowerShell commands and sophisticated web-based cloaking, signifies an adaptation to evolving cybersecurity defenses and a continuous search for new attack vectors that exploit human psychology and technical vulnerabilities in tandem.
The broader context of Sandworm’s operations paints a grim picture of persistent, state-sponsored cyber aggression. Sandworm, officially recognized as Unit 74455 of the Russian GRU, has a long and infamous history of targeting critical infrastructure, governmental entities, and private organizations, particularly in Ukraine. Their track record includes some of the most destructive cyberattacks in history, such as the BlackEnergy attacks on the Ukrainian power grid in 2015 and 2016, which caused widespread blackouts. They were also responsible for the NotPetya attack in 2017, a wiper malware disguised as ransomware that caused billions of dollars in damages globally, affecting shipping companies, pharmaceutical firms, and governmental systems. Their involvement in attempts to interfere with elections in various Western democracies further solidifies their reputation as a formidable and disruptive force in the cyber realm. The current ClickFix and COWARDDUCK campaigns are consistent with Sandworm’s modus operandi: highly adaptive, technically proficient, and strategically aligned with Russian geopolitical objectives.
The disclosure by CERT-UA comes amidst a broader trend of ClickFix becoming an increasingly effective social engineering technique across the cyber threat landscape. Numerous other malicious actors, both state-sponsored and criminal, have adopted similar lures to distribute a diverse range of malware. Recent reports indicate its use in spreading OXLOADER, a versatile loader; Mistic, a backdoor linked to the Kongtuke group; SCMBANKER, a banking trojan; ClickLock Stealer, a macOS-specific infostealer that kills applications; TELEPUZ, a new malware family; and ACR Stealer, another data exfiltration tool. The widespread adoption of ClickFix underscores its efficacy in bypassing traditional security layers by leveraging user trust and lack of technical awareness, making it a persistent and growing threat.
The implications of this ongoing campaign are multifaceted and deeply concerning. For Ukraine, these attacks represent a continuous effort to undermine national security, disrupt critical functions, and gather intelligence that could be used for military or political advantage. The data-stealing nature of GHETTOVIBE and COWARDDUCK suggests a primary objective of espionage, aiming to extract sensitive information from government officials, military personnel, and critical infrastructure operators. The compromise of mobile devices, in particular, opens up avenues for real-time surveillance and the potential for targeted disinformation campaigns.

Beyond the immediate targets, the use of sophisticated techniques like Cloaking.House, SMARTAXE, and EtherHiding highlights the global challenge of defending against advanced persistent threats (APTs). These methods are designed to be stealthy, adaptive, and resilient, requiring a multi-layered and intelligence-driven defense strategy. The abuse of legitimate services like Dropbox and Steam Community also poses a challenge for network defenders, who must differentiate between benign and malicious traffic on widely trusted platforms.
Official responses from CERT-UA emphasize the critical importance of cybersecurity awareness and robust defense mechanisms. Their alert serves as a timely warning to all Ukrainian organizations and citizens to exercise extreme caution when encountering unusual CAPTCHA requests or unsolicited APK files, especially those purporting to be security tools. Recommendations typically include:
- Enhanced User Education: Training users to recognize social engineering tactics, particularly those involving unusual prompts to execute commands.
- Strong Endpoint Protection: Implementing and regularly updating antivirus and endpoint detection and response (EDR) solutions on all devices.
- Network Segmentation and Monitoring: Isolating critical systems and continuously monitoring network traffic for anomalous activity, especially outbound connections to unusual or suspicious destinations.
- Patch Management: Ensuring all operating systems, applications, and security software are kept up-to-date to mitigate known vulnerabilities.
- Multi-Factor Authentication (MFA): Implementing MFA for all accounts to prevent unauthorized access even if credentials are stolen.
- Regular Backups: Maintaining offline, encrypted backups of critical data to ensure business continuity in the event of a successful attack.
- Incident Response Planning: Developing and practicing comprehensive incident response plans to rapidly detect, contain, and recover from cyberattacks.
The ongoing cyber conflict, exemplified by Sandworm’s latest ClickFix and COWARDDUCK campaigns, underscores the evolving nature of modern warfare, where digital battles are fought in parallel with physical ones. The continuous adaptation of state-sponsored threat actors necessitates an equally dynamic and resilient defense posture. As cyber capabilities become more sophisticated, the line between espionage, sabotage, and information warfare blurs, demanding heightened vigilance and international cooperation to safeguard digital infrastructures and protect populations from these persistent and pervasive threats. The international cybersecurity community remains keenly observant, analyzing these tactics to develop counter-measures and fortify global digital defenses against an adversary that shows no signs of relenting.
