UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware

UAC-0145, a Russian Sandworm group, tricks Ukrainians with fake ClickFix CAPTCHAs into installing data-stealing malware. Find out how to protect yourself.

lunes, 20 de julio de 2026 • 4 min read • Q2BSTUDIO Team

Sandworm Uses ClickFix to Distribute Malware in Ukraine

A recent campaign of cyberattacks has put the Ukrainian authorities on alert: the UAC-0145 group, linked to the feared Sandworm of Russian military intelligence, is using fake CAPTCHAs to trick users into installing malware on their devices. The technique, known as ClickFix, leverages the trust users place in security checkers to execute malicious actions. This new attack vector demonstrates once again how social engineering remains the weakest link in the cybersecurity chain, even in the face of highly technical organizations.

ClickFix is based on imitation of a legitimate CAPTCHA. The victim accesses a compromised website or receives a malicious link that displays a supposed human verification. When interacting with the fake CAPTCHA, you are instructed to press a key combination — such as Ctrl+V — which actually pastes a hidden command into your terminal. That command downloads and installs a Trojan that steals sensitive information: credentials, files, session cookies, and browsing data. All this without the user perceiving the threat until it is too late.

The UAC-0145 group is a subdivision of Sandworm, an advanced hacker unit belonging to the Russian GRU. Sandworm has been responsible for some of the most destructive cyberattacks of the past decade, including power outages in Ukraine in 2015 and 2016, as well as the NotPetya attack. Now, with ClickFix, they demonstrate an evolution towards stealthier but equally dangerous tactics, focused on data theft rather than destruction. This suggests a strategic shift toward intelligence and sensitive information collection.

Ukraine remains the priority target, but experts warn that this method can easily be replicated against other regions. Any company or institution that handles critical data could fall victim to a similar campaign adapted to its context. The ease with which an ordinary user can unknowingly execute the command makes ClickFix a cross-cutting threat, requiring no complex technical vulnerabilities, only psychological deception.

From a business perspective, this type of attack underscores the need to invest in proactive cybersecurity. Organizations must implement measures such as multi-factor authentication, network segmentation, continuous endpoint monitoring, and above all, staff training. An employee trained to recognize social engineering tactics is the first line of defense. In addition, having AI-based detection tools can identify anomalous behavior before malware is activated.

In this context, companies such as Q2BSTUDIO offer cybersecurity and pentesting services that help assess an organization's security posture. Simulating real attacks allows you to discover vulnerabilities before adversaries exploit them. They also provide advice on implementing security policies and selecting appropriate technologies, such as endpoint detection and response (EDR) solutions and threat intelligence systems.

Protection is not limited to perimeter security; It's also crucial to secure the applications that the company uses. Custom software development with security by design principles minimizes attack surfaces. Q2BSTUDIO develops custom applications that integrate security controls, strong authentication, and data encryption, both on-premise and in the cloud. This is especially relevant when using AWS and Azure cloud services, where shared responsibility demands secure configurations.

Artificial intelligence has become an indispensable ally in the fight against cybercrime. AI systems can analyze huge volumes of network traffic data, logs, and user behaviors to detect suspicious patterns in real time. AI agents, for example, can automate responses to minor incidents, freeing up the security team to focus on more complex threats. Q2BSTUDIO integrates AI for enterprises and intelligent agents into its cybersecurity solutions, offering an additional layer of predictive protection.

However, technology alone is not enough. Organizational culture must prioritize safety as a cross-cutting value. Companies that invest in services, business intelligence, and tools like Power BI can visualize security telemetry data, making it easier to make informed decisions. Constant monitoring of indicators of compromise and correlation of events are best practices that, together with an incident response plan, prepare the organization to react to attacks such as ClickFix.

The UAC-0145 attack also highlights the importance of cyber intelligence. Sharing threat intelligence between government and private entities allows you to anticipate new campaigns. Companies that are part of trusted communities and regularly update their systems and applications significantly reduce risk. In this sense, AWS and Azure cloud services offer native security tools that, when properly configured, can block many of the techniques used by ClickFix.

For SMEs and large corporations, the recommendation is clear: do not underestimate social engineering. Even the most robust systems go down if a user executes a malicious command. Ongoing training, simulating phishing attacks, and implementing least-privilege policies are essential steps. And having a technology partner that understands today's threat landscape makes all the difference. Q2BSTUDIO, with its expertise in cross-platform application development and cybersecurity, helps enterprises build strong defenses against emerging threats.

The case of UAC-0145 and the ClickFix technique is a reminder that cybersecurity is a dynamic field. Attackers are constantly evolving, and defenses must do the same. The combination of human training, advanced technology such as artificial intelligence and AI agents, and professional security services is the best strategy to protect digital assets. In a world where information is power, preventing data from falling into the wrong hands is both a responsibility and a competitive advantage.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.