CuraSec

Plan archived

UAC-0145 (Sandworm) Uses ClickFix CAPTCHAs to Deliver Info-Stealer

2026-07-20 13:16 UTC · The Hacker News · read the source ↗ #apt#social-engineering#sandworm
  • Engineer — Learn: ClickFix is a social-engineering technique, not a software vulnerability — no patch or config change applies. Understand the attack pattern (fake CAPTCHA prompts users to paste and run malicious commands) to inform user-awareness training and browser hardening policies.
  • SOC/IR — Plan: ClickFix produces detectable behavioral patterns — browser processes spawning cmd.exe or PowerShell, clipboard-sourced command execution — worth building or tuning detections for this quarter; no specific IOCs were published to support an immediate hunt.
  • Leader — Learn: Sandworm/GRU campaign currently focused on Ukrainian targets, making direct exposure unlikely for most US enterprises; useful situational awareness about adversary tradecraft evolution, but no immediate leadership action required.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.