A newly disclosed ClickFix malware campaign linked to UAC-0145, a threat cluster tracked by CERT-UA as a Sandworm sub-cluster, targeted Ukrainian organizations by abusing fake CAPTCHA prompts.
Victims were persuaded to execute malicious PowerShell commands that could deliver Windows malware.
Separately, UAC-0145 distributed the COWARDDUCK Android backdoor as APK files disguised as security tools through messaging applications.
The campaign highlights how social engineering, rather than software vulnerabilities, can compromise enterprise endpoints and mobile devices.
The latest ClickFix malware campaign shows how attackers continue to exploit user trust instead of software flaws. By presenting fake CAPTCHA verification prompts on compromised websites, the attackers reportedly convinced victims to execute malicious PowerShell commands themselves.
CERT-UA attributes the activity to UAC-0145, a threat cluster it tracks as a Sandworm sub-cluster. Public reporting indicates that UAC-0145 targeted Ukrainian users and organizations through several compromise methods.
Investigators assessed at least ten websites associated with the ClickFix activity as compromised during June and July 2026.
For enterprise security teams, the campaign demonstrates why endpoint protection, mobile device management, and user awareness must work together to reduce the risk of user-assisted attacks.
Incident at a Glance
Category
Details
Threat cluster
UAC-0145 (tracked by CERT-UA as a Sandworm sub-cluster)
Unlike traditional malware campaigns that exploit software vulnerabilities, this attack relied on user-assisted execution.
Compromised websites displayed fake CAPTCHA instructions directing visitors to open a Windows terminal and paste a PowerShell command. CERT-UA found that one version of the command could download and save a VBS file in the Windows Startup autorun directory, enabling the script to run when the user signed in.
Investigators observed the attackers using Cloaking.House to serve different content to different visitors and a custom tool called SMARTAXE to modify webpages dynamically and display CAPTCHA prompts based on visitor characteristics. The injected CAPTCHA content also used an EtherHiding technique to retrieve the domain name of a remote resource from an Ethereum smart contract.
OkoBot Malware Uses ClickFix and Fake GitHub Repositories
Discover how attackers use ClickFix lures and fake GitHub repositories to distribute malware.
Windows malware chain
CERT-UA identified several malware families used during different stages of the campaign.
Malware
Reported purpose
GHETTOVIBE
VBS payload used for persistence
SCOUTCURL
PowerShell reconnaissance script
FLUIDLEECH
Loader disguised as antivirus software
LOADLOOP
Malware loader
FREAKYPOLL
Python backdoor
Together, these components enabled reconnaissance, persistence, and the delivery of additional payloads. However, public reporting has not confirmed the complete objectives achieved during every intrusion.
How COWARDDUCK expanded the attack to Android devices
The campaign also included an Android backdoor known as COWARDDUCK, reportedly distributed as APK files masquerading as security tools through messaging applications.
According to the published technical analysis, the malware can collect:
Contacts
Documents and archives
Real-time geolocation
It also communicates through legitimate cloud services, including the Dropbox API, which may help malicious traffic blend with normal network activity. There is no indication that Dropbox itself was compromised.
This mobile component demonstrates how modern campaigns increasingly target both desktops and mobile devices, particularly in organizations that support BYOD or hybrid work environments.
Confirmed findings and remaining unknowns
Confirmed
Public reporting and CERT-UA’s advisory indicate that:
UAC-0145 used fake ClickFix CAPTCHA prompts as the initial lure.
Victims were instructed to execute PowerShell commands manually.
Multiple Windows malware families and the Android backdoor COWARDDUCK were identified.
Investigators found that UAC-0145 targeted Ukrainian users and organizations, and they identified at least ten compromised websites linked to the ClickFix activity during June and July 2026.
Not publicly confirmed
At the time of writing, public reporting has not confirmed:
The total number of affected organizations
Large-scale data exfiltration
Credential theft
Ransomware deployment
The attackers’ full post-compromise objectives
As the investigation continues, additional technical details may emerge.
Enterprise security lessons from the ClickFix malware attack
The campaign reinforces several important security lessons.
Social engineering can bypass technical defenses by persuading users to execute malicious commands.
PowerShell remains a common technique for malware delivery and post-exploitation activity.
Mobile devices should be included in enterprise security strategies because attackers increasingly target Android alongside Windows.
BYOD environments require consistent security policies across corporate and personally owned devices.
Security awareness training should specifically cover fake CAPTCHA and ClickFix-style attacks.
Organizations should also review controls around PowerShell usage, application installation, endpoint compliance, and mobile device governance to reduce exposure to similar campaigns.
How Hexnode helps reduce enterprise risk
While no platform can eliminate every social engineering attack, layered security controls can significantly reduce organizational risk.
Attack stage
Relevant Hexnode capability
Unauthorized application installation
Hexnode UEM application management and policy enforcement
Android device governance
Hexnode UEM Android Enterprise and BYOD management
Device compliance
Hexnode UEM compliance policies and endpoint restrictions
Endpoint investigation
Hexnode XDR endpoint investigation and historical activity analysis
Incident response
Hexnode XDR process termination and device isolation
These capabilities can help organizations strengthen endpoint governance, investigate suspicious activity, and support incident response after a compromise.
Featured resource
Introduction to Hexnode XDR
Learn how Hexnode XDR helps security teams detect, investigate, and respond to endpoint threats with unified visibility and response capabilities.
Fake CAPTCHA attacks exploit user trust rather than software vulnerabilities. By persuading users to execute commands themselves, attackers may evade some protections designed to block malicious links, attachments, or downloaded files. This technique also appears more legitimate because it mimics familiar verification steps.
Can ClickFix attacks affect managed enterprise devices?
Yes. Managed devices can still be affected if users manually execute malicious commands. However, organizations can reduce risk through application controls, endpoint policies, PowerShell restrictions where appropriate, and security awareness training.
Why do attackers use legitimate cloud services like Dropbox?
Attackers sometimes use legitimate cloud platforms to transfer commands or stolen data because traffic to trusted services may blend with normal network activity. In this campaign, public reporting indicated that the Android malware communicated through the Dropbox API. There is no evidence that Dropbox itself was compromised.
How should organizations respond to ClickFix-style attacks?
Organizations should isolate affected devices, investigate PowerShell activity, identify persistence mechanisms, review endpoint and mobile device logs, and educate users about fake verification prompts. They should also reset credentials if compromise is suspected and follow their incident response procedures.
By using ClickFix and PowerShell against Windows devices while separately distributing malicious APK files to Android users, the activity highlights the need for coordinated endpoint and mobile security.
Enterprises should treat ClickFix-style attacks as more than a phishing problem. Combining user education with device compliance, application management, endpoint investigation, and incident response can help reduce the impact of similar campaigns in the future.
Detect Threats Before They Become Breaches
See how Hexnode XDR helps security teams investigate suspicious endpoint activity, accelerate incident response, and strengthen enterprise defenses.
I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.