Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1972+ Articles
150+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. UAC-0145 Uses ClickFix CAPTCHAs to Deliver Malware to Ukrainian Devices
UAC-0145 Uses ClickFix CAPTCHAs to Deliver Malware to Ukrainian Devices
NEWS

UAC-0145 Uses ClickFix CAPTCHAs to Deliver Malware to Ukrainian Devices

Russian state-sponsored threat actor UAC-0145 is deploying ClickFix-style fake CAPTCHA prompts to trick Ukrainian targets into self-installing data-stealing malware. CERT-UA has issued an advisory urging organizations to apply mitigations and raise user awareness.

Dylan H.

News Desk

July 19, 2026
3 min read

Russian state-sponsored threat actors operating under the designation UAC-0145 have been observed deploying the ClickFix social engineering technique to compromise Ukrainian targets, according to a new advisory from Ukraine's Computer Emergency Response Team (CERT-UA).

What Is ClickFix?

ClickFix is a well-documented attack technique that presents victims with a fake browser or CAPTCHA verification prompt. The prompt instructs the user to press Win+R, open PowerShell or the Run dialog, and paste a malicious command — effectively having the victim execute malware themselves. The technique sidesteps many traditional endpoint defenses because the user initiates the execution, bypassing application whitelisting and reducing the chance of automated detection at the email or browser gateway.

The strategy gained significant traction among both cybercriminal and state-sponsored groups in 2025 and has since become a standard tool in the APT playbook.

UAC-0145 Campaign Details

According to CERT-UA, UAC-0145 has been leveraging ClickFix-style fake CAPTCHA pages to deliver data-stealing malware to Ukrainian individuals and organizations. The lure pages are crafted to appear as legitimate human-verification screens — the kind commonly encountered on real websites. Victims who complete the fake verification unknowingly run a malicious payload on their device.

The ultimate goal of the campaign is data exfiltration: the malware is designed to harvest credentials, documents, and other sensitive data from compromised machines, consistent with Russia's ongoing intelligence-collection operations against Ukraine during the active conflict.

Why This Matters

State-sponsored use of ClickFix represents a convergence of high-sophistication threat actors with a technique originally popularized by opportunistic cybercriminals. UAC-0145 is one of several Russia-linked groups that CERT-UA tracks as conducting persistent cyber operations against Ukrainian government, military, and critical infrastructure targets.

The use of self-execution lures is notable because it:

  • Bypasses EDR/AV that monitors process spawning from browsers or email clients
  • Requires no vulnerability — the victim executes the payload themselves
  • Scales easily — the fake CAPTCHA pages can be embedded in phishing emails, compromised sites, or malicious ads

Mitigation Recommendations

CERT-UA and cybersecurity researchers recommend the following defenses against ClickFix-style attacks:

  • User awareness training: Educate users that no legitimate CAPTCHA or browser verification ever requires them to open a terminal or paste commands
  • Restrict PowerShell and Run dialog access on endpoints where it is not required for business operations, using AppLocker or Windows Defender Application Control (WDAC)
  • Enable Script Block Logging in PowerShell to capture executed commands for investigation
  • Deploy endpoint detection rules for commands that include patterns like mshta, curl, Invoke-Expression, or base64-encoded payloads executed via the Run dialog
  • Monitor DNS and network traffic for connections to known ClickFix infrastructure IOCs published by CERT-UA

References

  • The Hacker News — UAC-0145 Uses ClickFix CAPTCHAs
  • CERT-UA Advisory Portal
#Malware#APT#Russia#ClickFix#Ukraine#CERT-UA#Social Engineering

Related Articles

Gamaredon Expands Ukraine Attacks with New Malware and Cloud Abuse

Russian FSB-linked APT group Gamaredon has mounted 35 distinct spear-phishing campaigns against Ukrainian targets in 2025, deploying an expanded malware...

5 min read

Russian APT Gamaredon Upgrades Its Arsenal, Requiring New Defenses

ESET research reveals FSB-sponsored Gamaredon has significantly upgraded its C2 infrastructure obfuscation and malware delivery capabilities, running 35...

3 min read

Russian-Linked CANFAIL Malware Targets Ukrainian Defense

Google Threat Intelligence Group attributes a previously undocumented JavaScript malware called CANFAIL to a Russian-linked threat actor targeting...

3 min read
Back to all News