The record
Written from the 1 report below. Nothing here is unsourced.
- Ukraine's cyber authority CERT-UA says a Russian GRU-linked hacking group, UAC-0145 (part of Sandworm), is tricking Ukrainian users into infecting their own devices with data-stealing malware.
- The attackers use fake CAPTCHA checks on compromised websites that instruct visitors to run a malicious PowerShell command, with at least 10 websites compromised between June and July 2026.
- The campaign also targets Android users through malicious APK files disguised as security tools and spread via messaging apps, capable of stealing contacts, files, and real-time location data.
- This marks a shift toward the ClickFix social engineering technique for a group that previously used trojanized installers and fake antivirus software.
What to watch next
- Whether CERT-UA identifies more compromised websites beyond the 10 assessed so far
- Any expansion of the campaign beyond Ukrainian targets
- Further use of ClickFix tactics by state-sponsored groups
Coverage1
1 report
English national1
All filed from India
Named Ukraine · Cloaking.House · COWARDDUCK · EtherHiding · FLUIDLEECH · FREAKYPOLL · GHETTOVIBE · LOADLOOP · OXLOADER · SCOUTCURL · SMARTAXE · CERT-UA
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
