Now, even Russia's most elite hackers are using Clickfix to infect devices
| Source: Ars Technica AI
Tags: Sandworm, GRU, Clickfix, Ukraine, CERT-UA, cyberattack, FreakyPoll
Russia's Sandworm GRU hacking unit has adopted Clickfix social-engineering attacks against Ukrainian organizations since spring 2026, Ukraine's CERT-UA confirms — marking the technique's shift from financially-motivated criminals to state-sponsored espionage.
Details
Ukraine's Computer Emergency Response Team (CERT-UA) issued an advisory Wednesday confirming that Sandworm — the GRU's most technically capable hacking unit, tied to past attacks on Ukrainian power grids — has operated Clickfix campaigns since spring 2026, compromising at least one Ukrainian organization. Clickfix presents victims with a fake CAPTCHA on attacker-controlled websites, instructing them to copy a PowerShell command and paste it into their own terminal to verify they are human. This sidesteps most endpoint defenses because the user executes the payload themselves. Ukraine's CERT identified 10 compromised websites using this method. The attack chain deploys five malware layers: GHETTOVIBE drops a VBS file into the Windows Startup folder for persistence; SCOUTCURL runs PowerShell reconnaissance gathering browser data, installed programs, and system info; FreakyPoll (a Python backdoor) is installed on high-value targets; FluidLeech masquerades as antivirus software; and LoadLoop completes the chain. Sandworm is also using the Cloaking.House traffic-filtering service to serve malicious content selectively to high-value visitors only. The significance is that Clickfix was previously a low-sophistication criminal tool. Sandworm's adoption suggests it succeeds even against security-aware government and defense targets, and enterprises should add paste-and-run attack vectors to security training programs.