Russian state-sponsored threat actor UAC-0145, a sub-cluster of the Sandworm group (GRU), is targeting Ukrainian users through a social engineering campaign utilizing the ClickFix strategy. This technique involves presenting victims with fake CAPTCHA checks on compromised websites, which then instruct them to execute malicious PowerShell commands. These commands typically lead to the deployment of various malware, such as the GHETTOVIBE VBS script for persistence and SCOUTCURL for system reconnaissance.
The campaign also employs advanced delivery mechanisms including EtherHiding, which leverages Ethereum smart contracts to retrieve command-and-control domains, and the SMARTAXE tool for dynamic web content alteration. Beyond Windows targets, the group has been observed distributing an Android backdoor named COWARDDUCK disguised as security software. This multi-platform attack suite allows the threat actors to exfiltrate sensitive files, real-time geolocation, and contacts from infected devices using cloud APIs like Dropbox.
Top comments (0)