Plan
archived
UAC-0145 (Sandworm) Uses ClickFix CAPTCHAs to Deliver Info-Stealer
- Engineer — Learn: ClickFix is a social-engineering technique, not a software vulnerability — no patch or config change applies. Understand the attack pattern (fake CAPTCHA prompts users to paste and run malicious commands) to inform user-awareness training and browser hardening policies.
- SOC/IR — Plan: ClickFix produces detectable behavioral patterns — browser processes spawning cmd.exe or PowerShell, clipboard-sourced command execution — worth building or tuning detections for this quarter; no specific IOCs were published to support an immediate hunt.
- Leader — Learn: Sandworm/GRU campaign currently focused on Ukrainian targets, making direct exposure unlikely for most US enterprises; useful situational awareness about adversary tradecraft evolution, but no immediate leadership action required.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.