BTC$63,083+0.50% LTC$44.11+1.19% XMR$409.26+2.83%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Jul 16, 2026 · 2 min read · Original story

Sandworm hackers have a CAPTCHA trick for Ukrainians

Sandworm hackers have a CAPTCHA trick for Ukrainians
Sandworm hackers have a CAPTCHA trick for Ukrainians

Russian military intelligence hackers have begun using fake CAPTCHA prompts on compromised websites to trick Ukrainian targets into infecting their own computers, researchers have found.

In a report published Wednesday, Ukraine's computer emergency response team (CERT-UA) said it observed a shift this spring and summer in how the Kremlin-backed hacking group Sandworm gains initial access to the systems of Ukrainian targets.

The agency said the group has increasingly adopted a version of the social engineering technique known as ClickFix. In this case, victims are directed to compromised websites displaying a fake CAPTCHA security check designed to distinguish humans from computers.

Rather than verifying they are human, users are instructed to copy and paste a PowerShell command into their Windows computers. The command downloads malware that allows hackers to maintain access to the computer and deploy additional malicious tools later.

The initial malware, dubbed GhettoVibe, can be followed by a reconnaissance tool called ScoutCurl, which collects information about the infected computer, including system details, installed software, files and browser data, to help attackers determine whether the target is worth further compromising. Researchers also observed two malware loaders: FluidLeech, disguised as antivirus removal software, and LoadLoop.

CERT-UA said it observed the ClickFix technique on more than 10 compromised websites during June and July. The agency did not report the number of compromised devices.

Despite its shift toward ClickFix attacks, Sandworm continues to rely on familiar social engineering methods as well.The agency warned that the group targets Android devices with malware disguised as security applications and distributed through messaging apps. Once installed, the malware can secretly collect contacts, files, device information and real-time location data.

For years, one of Sandworm's primary tactics involved distributing backdoored copies of Microsoft Windows and Office installers through torrent sites, allowing the group to quietly compromise victims who downloaded pirated software.

CERT-UA said that in at least one case, such an infection enabled the hackers to establish a foothold inside a Ukrainian government network before launching a destructive cyberattack against a central executive authority.

Another tactic Sandworm has relied on throughout Russia's war in Ukraine is targeting victims through the Signal messaging app by convincing them to install bogus antivirus software. According to CERT-UA, the hackers often spent weeks building trust with military personnel and other targets before asking them to run malicious files, sometimes even offering cash payments in exchange for following their instructions.

Sandworm, which Western governments and cybersecurity researchers link to Russia's military intelligence agency, the GRU, has been active since at least 2013 and is responsible for some of Russia's most high-profile destructive cyberattacks, including attacks on Ukraine's power grid.

References in this story

  1. CERT-UA cert.gov.ua Урядова команда реагування на комп’ютерні надзвичайні події України, яка функціонує в складі Державної служби спеціального зв’язку та захисту інформації України.
  2. Think before you Click(Fix): Analyzing the ClickFix social engineering technique | Microsoft Security Blog www.microsoft.com The ClickFix social engineering technique has been growing in popularity, with campaigns targeting thousands of enterprise and end-user devices daily. This technique exploits users’ tendency to resolve technical issues…
  3. Russian state hackers spy on Ukrainian military through Signal app therecord.media Russian state-backed hackers are increasingly targeting Signal messenger accounts — including those used by Ukrainian military personnel and government officials — in an effort to access sensitive information that could…
  4. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your business.
  5. Daryna Antoniuk (@darynant.bsky.social) bsky.app Cybersecurity Reporter at Recorded Future News. Ex at The Kyiv Independent/Forbes/The Kyiv Post 📍Kyiv, Ukraine

Guides related to this story

← Back to all news