{"id":63743,"date":"2026-07-17T13:42:27","date_gmt":"2026-07-17T17:42:27","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=63743"},"modified":"2026-07-17T13:42:27","modified_gmt":"2026-07-17T17:42:27","slug":"sandworm-clickfix-ukraine","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/sandworm-clickfix-ukraine\/","title":{"rendered":"Sandworm adopts Clickfix to infect Ukrainian devices"},"content":{"rendered":"<p>The Russian military intelligence unit known as Sandworm has adopted the Clickfix <a href=\"https:\/\/overcentral.com\/en\/scattered-spider-hackers-sentenced\/\" title=\"UK Jails Two Hackers, Cripples Scattered Spider\" data-iacss-internal=\"1\">social engineering<\/a> technique to compromise networks of sensitive Ukrainian organizations, according to a warning from Ukraine&#8217;s Computer Emergency <a href=\"https:\/\/overcentral.com\/en\/cisa-github-credential-leak\/\" title=\"CISA Postmortem Exposes Gaps in Response to GitHub Credential Leak\" data-iacss-internal=\"1\">Response<\/a> Team (<a href=\"https:\/\/cert.gov.ua\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">CERT-UA<\/a>). The shift marks a notable escalation: Clickfix, previously a tool of financially motivated cybercriminals, is now being weaponized by one of the world&#8217;s most dangerous state-sponsored hacking groups.<\/p>\n<h2>What Is Clickfix?<\/h2>\n<p>Clickfix is an attack method that tricks users into executing malicious commands through a fake CAPTCHA challenge. Victims visiting a compromised or attacker-controlled website are presented with a CAPTCHA that requires them to copy a jumble of text and paste it into a terminal window. That text contains PowerShell or other scripts that, once run, install malware or exfiltrate sensitive data. The technique has surged in popularity over the last year because it bypasses traditional web filters and relies on the user&#8217;s own trust in CAPTCHA as a legitimate security measure.<\/p>\n<h2>Sandworm&#8217;s Clickfix Campaign Targets Ukraine<\/h2>\n<p>CERT-UA reported <a href=\"https:\/\/overcentral.com\/en\/anthropic-restores-claude-fable-5-access\/\" title=\"Anthropic Restores Claude Fable 5 Access on Wednesday\" data-iacss-internal=\"1\">Wednesday<\/a> that Sandworm\u2014operating under the GRU, Russia&#8217;s military intelligence agency\u2014began deploying Clickfix attacks in spring 2025 and has continued through the summer. Investigators discovered at least ten compromised websites that hosted fake CAPTCHA pages instructing visitors to run PowerShell commands. One of the earliest malware payloads identified in the campaign is a reconnaissance script named GHETTOVIBE, which collects system information, installed programs, files, and browser data. Once the threat is assessed, a second-stage tool called SCOUTCURL\u2014a PowerShell-based reconnaissance and exfiltration script\u2014transmits the stolen data back to the attackers.<\/p>\n<p>Machines deemed valuable are then loaded with more destructive follow-on malware, including FreakyPoll, a custom Sandworm backdoor. The advisory notes that at least one organization suffered a full network compromise after an infected device was connected to its internal systems.<\/p>\n<p>The attack chain typically works like this:<\/p>\n<ul>\n<li>User visits a compromised website and sees a fake CAPTCHA.<\/li>\n<li>User copies and pastes a PowerShell script into the terminal to &#8220;prove&#8221; they are human.<\/li>\n<li>The script downloads and executes a Visual Basic script (e.g., GHETTOVIBE) placed in the Startup folder.<\/li>\n<li>That script runs SCOUTCURL for reconnaissance and exfiltration.<\/li>\n<li>If the target is valuable, additional malware such as FreakyPoll is installed to establish persistent backdoor access.<\/li>\n<\/ul>\n<h2>Why This Matters Beyond Ukraine<\/h2>\n<p>Sandworm has a long history of destructive cyberattacks, including the NotPetya wiper attack in 2017 and repeated strikes on Ukrainian critical infrastructure. The adoption of Clickfix suggests the group is actively diversifying its initial-access methods to evade detection. While this campaign is currently focused on Ukrainian targets, the same techniques can be easily retooled against organizations in the US, UK, Australia, and Canada, especially those involved in defense, energy, or diplomatic sectors.<\/p>\n<p>State-sponsored groups are increasingly borrowing effective social engineering tactics from cybercriminal ecosystems, making it harder for defenders to distinguish between financially motivated and geopolitical threats. The use of fake CAPTCHAs is particularly insidious because it exploits a routine web behavior that most users are trained to trust.<\/p>\n<h2>How Organizations Can Defend Against Clickfix Attacks<\/h2>\n<p>Because Clickfix relies on user interaction, the first line of defense is awareness. Security teams should train employees never to paste unknown commands into a terminal\u2014especially from a CAPTCHA, which never requires that action. On the technical side, organizations should deploy multi-layer endpoint protection that includes behavioral analysis and PowerShell logging. Restricting PowerShell execution for standard users and implementing application whitelisting can block many Clickfix attack chains before they compromise a system.<\/p>\n<p>For incident responders, monitoring for unexpected PowerShell execution from browsers or user-initiated scripts is a key detection signal. Organizations in high-risk sectors\u2014such as energy, defense, and government\u2014should treat any unexpected CAPTCHA challenge as a potential attack vector and investigate immediately. Finally, maintaining offline backups and a tested incident response plan remains essential, as Sandworm&#8217;s ultimate objective in any campaign is often data destruction or long-term espionage.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Russian military intelligence unit known as Sandworm has adopted the Clickfix social engineering technique to compromise networks of sensitive Ukrainian organizations, according to a warning from Ukraine&#8217;s Computer Emergency Response Team (CERT-UA). The shift marks a notable escalation: Clickfix, previously a tool of financially motivated cybercriminals, is now being weaponized by one of the [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":83963,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/63743.png","fifu_image_alt":"Sandworm adopts Clickfix to infect Ukrainian devices","footnotes":""},"categories":[349],"tags":[],"class_list":["post-63743","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/63743.png","fifu_image_alt":"Sandworm adopts Clickfix to infect Ukrainian devices","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63743","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=63743"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63743\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/83963"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=63743"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=63743"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=63743"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}