UAC-0145, a Russian state-sponsored group operating under the Sandworm banner of Russia's GRU, has launched targeted attacks against Ukrainian devices using the ClickFix social engineering technique.
The Computer Emergency Response Team of Ukraine (CERT-UA) identified the campaign, which exploits a deceptive method that mimics CAPTCHA verification screens. Victims encounter fake security prompts during web browsing. When clicked, these malicious CAPTCHAs trigger downloads of data-stealing malware rather than completing legitimate verification.
The ClickFix tactic preys on user trust in familiar interface elements. Most people recognize and habitually click CAPTCHA challenges without suspicion. UAC-0145 weaponizes this behavior by inserting counterfeit versions into compromised websites or through advertisements. Once executed, the malware establishes persistence on infected systems and begins harvesting sensitive information.
UAC-0145 operates as part of Sandworm, an advanced persistent threat group with a well-documented history of destructive operations against Ukrainian infrastructure. The group has previously conducted attacks on power grids, water systems, and government networks. This campaign represents a shift toward data theft operations targeting individual users alongside critical infrastructure targets.
The targeting of Ukrainian devices aligns with broader Russian cyber operations against Ukraine. Residential infections expand attack surface for reconnaissance, credential harvesting, and potential lateral movement into organizational networks where infected individuals work.
Organizations should implement technical controls to limit user exposure to malicious content. Blocking advertisement networks known to serve ClickFix variants and deploying web filtering prevent delivery of these fake CAPTCHAs. Endpoint detection tools capable of identifying malware behavior during execution provide additional protection.
Individual users face direct risk from this campaign. Educational messaging about verifying CAPTCHA authenticity before interaction offers practical defense. Legitimate CAPTCHA systems never require
