"The mentioned command, as an example, could be intended for downloading and saving a VBS file in the Startup autorun directory; one of the variants of such a program was called GHETTOVIBE," CERT‑UA warned in an alert.
Who CERT‑UA says is behind the campaign
Ukraine's Computer Emergency Response Team (CERT‑UA) has attributed a recent campaign to UAC‑0145, which it describes as a sub‑cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's primary foreign military intelligence agency. The advisory links the group to a set of operations that use social engineering on legitimate websites to trick visitors into executing commands and installing data‑stealing malware.
How ClickFix CAPTCHAs are being misused
The attackers are exploiting a technique known as ClickFix: fake CAPTCHA checks injected into compromised websites that instruct visitors to run a PowerShell command in their terminals. CERT‑UA notes the injected command can download and place a VBS file into the Windows Startup autorun directory — an example variant named GHETTOVIBE is cited. To shape what different visitors see, the adversary side‑loads a traffic‑filtering service called Cloaking.House and a bespoke tool named SMARTAXE that dynamically alters page content and injects the CAPTCHA.
Tools and malware families identified in infected endpoints
CERT‑UA's alert lists a chain of tools and payloads observed in affected systems. A PowerShell reconnaissance script called SCOUTCURL harvests basic details from infected machines. The campaign deploys loaders named FLUIDLEECH and LOADLOOP — with FLUIDLEECH masquerading as software for removing computer viruses — and a Python backdoor called FREAKYPOLL. The disclosure positions these components as the malware ecosystem supporting the ClickFix delivery.
Android backdoor COWARDDUCK and its capabilities
In parallel to Windows‑focused ClickFix delivery, CERT‑UA reports the use of malicious Android packages (APKs) distributed via messaging apps and disguised as security tools. The embedded backdoor, tracked as COWARDDUCK, is described as full‑featured: it clandestinely collects contacts, streams real‑time geolocation, and exfiltrates files that match a specified set of extensions (".conf," ".json," ".ovpn," ".txt," ".doc," ".docx," ".xls," ".xlsx," ".pptx," ".zip," and ".rar") from named directories ("DCIM," "Documents," "Downloads," "Pictures," and "Alarms"). COWARDDUCK uses the Dropbox cloud API to upload collected files and can retrieve commands or data from an external server or from legitimate sites such as steamcommunity[.]com.
At least 10 compromised websites, and an unusual domain-retrieval trick
CERT‑UA assessed that at least 10 websites were compromised between June and July 2026 as part of this campaign. The injected CAPTCHA content uses an EtherHiding technique: retrieving the domain name of the remote resource from an Ethereum smart contract via an address embedded in the page source. That chain — Ethereum smart contract → domain lookup → injected CAPTCHA → PowerShell execution — illustrates the layered technical measures the actors applied to evade simple detection and to make takedown more complex.
What this means for technologists, policymakers, and end users
- Technologists and security teams: Watch for indicators tied to the named tools — SCOUTCURL, FLUIDLEECH, LOADLOOP, FREAKYPOLL, GHETTOVIBE, and COWARDDUCK — and for unusual PowerShell execution triggered by web‑delivered CAPTCHAs, plus Cloaking.House and SMARTAXE‑style content‑alteration signals.
- Policymakers and regulators: The use of Cloaking.House and EtherHiding via Ethereum smart contracts presents novel attribution and takedown frictions that will matter to cyber policy, legal responses, and cross‑border cooperation around compromised web infrastructure.
- End users and the general public: CERT‑UA's account underscores the specific social‑engineering hook to watch for: CAPTCHAs that instruct users to run terminal or PowerShell commands, and APKs received through messaging apps that claim to be security tools.
CERT‑UA frames this campaign as a tactical shift for the Kremlin‑backed crew: a move away from previously observed delivery mechanisms such as trojanized Windows or Office installers and bogus antivirus shared on messaging apps. The alert also places ClickFix alongside a broader set of abuses, noting the technique continues to deliver a range of stealers and loaders — including OXLOADER, Mistic, SCMBANKER, ClickLock Stealer, TELEPUZ, and ACR Stealer.
The record from CERT‑UA is granular about the methods and families involved and explicit about scope — at least 10 compromised sites between June and July 2026 — but it leaves the operational work implied: locating and remediating the injected CAPTCHA content, identifying SMARTAXE and Cloaking.House traffic, and hunting for the named toolset across affected networks. For defenders in Ukraine and beyond, the immediate task is concrete and technical: find the PowerShell execution points, clean the Startup autorun artifacts like GHETTOVIBE, and block COWARDDUCK‑style exfiltration paths.




