UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Summary

Russian state-sponsored threat actors, specifically UAC-0145 (a sub-cluster of Sandworm), are using a "ClickFix" strategy to trick Ukrainian targets into infecting their own devices with data-stealing malware. This tactic involves convincing users to download and execute malicious files disguised as legitimate software updates or fixes.

IFF Assessment

FOE

This article details a specific tactic employed by a known advanced persistent threat group, indicating a current and active threat to defenders.

Defender Context

Defenders should be aware of social engineering tactics that trick users into downloading and executing files, particularly in geopolitical conflict zones. Training users to recognize and report suspicious downloads, and implementing robust endpoint detection and response (EDR) solutions are crucial countermeasures.

Read Full Story →