Nora
Blake

UAC-0145 Uses ClickFix Against Windows Devices and COWARDDUCK Against Android

Nora Blake

Jul 28, 2026

6 min read

UAC-0145 Uses ClickFix Against Windows Devices and COWARDDUCK Against Android

TL; DR

  • A newly disclosed ClickFix malware campaign linked to UAC-0145, a threat cluster tracked by CERT-UA as a Sandworm sub-cluster, targeted Ukrainian organizations by abusing fake CAPTCHA prompts.
  • Victims were persuaded to execute malicious PowerShell commands that could deliver Windows malware.
  • Separately, UAC-0145 distributed the COWARDDUCK Android backdoor as APK files disguised as security tools through messaging applications.
  • The campaign highlights how social engineering, rather than software vulnerabilities, can compromise enterprise endpoints and mobile devices.

Introduction

The latest ClickFix malware campaign shows how attackers continue to exploit user trust instead of software flaws. By presenting fake CAPTCHA verification prompts on compromised websites, the attackers reportedly convinced victims to execute malicious PowerShell commands themselves.

CERT-UA attributes the activity to UAC-0145, a threat cluster it tracks as a Sandworm sub-cluster. Public reporting indicates that UAC-0145 targeted Ukrainian users and organizations through several compromise methods.

Investigators assessed at least ten websites associated with the ClickFix activity as compromised during June and July 2026.

For enterprise security teams, the campaign demonstrates why endpoint protection, mobile device management, and user awareness must work together to reduce the risk of user-assisted attacks.

Incident at a Glance

Category  Details 
Threat cluster  UAC-0145 (tracked by CERT-UA as a Sandworm sub-cluster) 
Attack type  Social engineering malware campaign 
Initial access  Fake ClickFix CAPTCHA prompts 
Primary targets  Ukrainian organizations 
Platforms targeted through separate attack paths  Windows through ClickFix prompts; Android through disguised APK files 
Windows malware  GHETTOVIBE, SCOUTCURL, FLUIDLEECH, LOADLOOP, FREAKYPOLL 
Android malware  COWARDDUCK 
ClickFix findings publicly disclosed  July 2026 

How the ClickFix malware campaign worked

Unlike traditional malware campaigns that exploit software vulnerabilities, this attack relied on user-assisted execution.

Compromised websites displayed fake CAPTCHA instructions directing visitors to open a Windows terminal and paste a PowerShell command. CERT-UA found that one version of the command could download and save a VBS file in the Windows Startup autorun directory, enabling the script to run when the user signed in.

Investigators observed the attackers using Cloaking.House to serve different content to different visitors and a custom tool called SMARTAXE to modify webpages dynamically and display CAPTCHA prompts based on visitor characteristics. The injected CAPTCHA content also used an EtherHiding technique to retrieve the domain name of a remote resource from an Ethereum smart contract.

Windows malware chain

CERT-UA identified several malware families used during different stages of the campaign.

Malware  Reported purpose 
GHETTOVIBE  VBS payload used for persistence 
SCOUTCURL  PowerShell reconnaissance script 
FLUIDLEECH  Loader disguised as antivirus software 
LOADLOOP  Malware loader 
FREAKYPOLL  Python backdoor 

Together, these components enabled reconnaissance, persistence, and the delivery of additional payloads. However, public reporting has not confirmed the complete objectives achieved during every intrusion.

How COWARDDUCK expanded the attack to Android devices

The campaign also included an Android backdoor known as COWARDDUCK, reportedly distributed as APK files masquerading as security tools through messaging applications.

According to the published technical analysis, the malware can collect:

  • Contacts
  • Documents and archives
  • Real-time geolocation

It also communicates through legitimate cloud services, including the Dropbox API, which may help malicious traffic blend with normal network activity. There is no indication that Dropbox itself was compromised.

This mobile component demonstrates how modern campaigns increasingly target both desktops and mobile devices, particularly in organizations that support BYOD or hybrid work environments.

Confirmed findings and remaining unknowns

Confirmed

Public reporting and CERT-UA’s advisory indicate that:

  • UAC-0145 used fake ClickFix CAPTCHA prompts as the initial lure.
  • Victims were instructed to execute PowerShell commands manually.
  • Multiple Windows malware families and the Android backdoor COWARDDUCK were identified.

Investigators found that UAC-0145 targeted Ukrainian users and organizations, and they identified at least ten compromised websites linked to the ClickFix activity during June and July 2026.

Not publicly confirmed

At the time of writing, public reporting has not confirmed:

  • The total number of affected organizations
  • Large-scale data exfiltration
  • Credential theft
  • Ransomware deployment
  • The attackers’ full post-compromise objectives

As the investigation continues, additional technical details may emerge.

Enterprise security lessons from the ClickFix malware attack

The campaign reinforces several important security lessons.

  • Social engineering can bypass technical defenses by persuading users to execute malicious commands.
  • PowerShell remains a common technique for malware delivery and post-exploitation activity.
  • Mobile devices should be included in enterprise security strategies because attackers increasingly target Android alongside Windows.
  • BYOD environments require consistent security policies across corporate and personally owned devices.
  • Security awareness training should specifically cover fake CAPTCHA and ClickFix-style attacks.

Organizations should also review controls around PowerShell usage, application installation, endpoint compliance, and mobile device governance to reduce exposure to similar campaigns.

How Hexnode helps reduce enterprise risk

While no platform can eliminate every social engineering attack, layered security controls can significantly reduce organizational risk.

Attack stage  Relevant Hexnode capability 
Unauthorized application installation  Hexnode UEM application management and policy enforcement 
Android device governance  Hexnode UEM Android Enterprise and BYOD management 
Device compliance  Hexnode UEM compliance policies and endpoint restrictions 
Endpoint investigation  Hexnode XDR endpoint investigation and historical activity analysis 
Incident response  Hexnode XDR process termination and device isolation 

These capabilities can help organizations strengthen endpoint governance, investigate suspicious activity, and support incident response after a compromise.

Introduction to Hexnode XDR
Featured resource

Introduction to Hexnode XDR

Learn how Hexnode XDR helps security teams detect, investigate, and respond to endpoint threats with unified visibility and response capabilities.

Download the Presentation

FAQs

Fake CAPTCHA attacks exploit user trust rather than software vulnerabilities. By persuading users to execute commands themselves, attackers may evade some protections designed to block malicious links, attachments, or downloaded files. This technique also appears more legitimate because it mimics familiar verification steps.

Yes. Managed devices can still be affected if users manually execute malicious commands. However, organizations can reduce risk through application controls, endpoint policies, PowerShell restrictions where appropriate, and security awareness training.

Attackers sometimes use legitimate cloud platforms to transfer commands or stolen data because traffic to trusted services may blend with normal network activity. In this campaign, public reporting indicated that the Android malware communicated through the Dropbox API. There is no evidence that Dropbox itself was compromised.

Organizations should isolate affected devices, investigate PowerShell activity, identify persistence mechanisms, review endpoint and mobile device logs, and educate users about fake verification prompts. They should also reset credentials if compromise is suspected and follow their incident response procedures.

Conclusion

The ClickFix malware campaign attributed to UAC-0145 demonstrates how modern attackers increasingly rely on social engineering instead of software exploits.

By using ClickFix and PowerShell against Windows devices while separately distributing malicious APK files to Android users, the activity highlights the need for coordinated endpoint and mobile security.

Enterprises should treat ClickFix-style attacks as more than a phishing problem. Combining user education with device compliance, application management, endpoint investigation, and incident response can help reduce the impact of similar campaigns in the future.

Share

Nora Blake

I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.