{"id":856,"date":"2026-07-28T10:40:27","date_gmt":"2026-07-28T05:10:27","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=856"},"modified":"2026-08-19T10:54:55","modified_gmt":"2026-08-19T05:24:55","slug":"clickfix-malware-uac-0145-sandworm","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/","title":{"rendered":"UAC-0145 Uses ClickFix Against Windows Devices and COWARDDUCK Against Android"},"content":{"rendered":"<h2>Introduction<\/h2>\n<p>The latest ClickFix malware campaign shows how attackers continue to exploit user trust instead of software flaws. By presenting fake CAPTCHA verification prompts on compromised websites, the attackers reportedly convinced victims to execute malicious PowerShell commands themselves.<\/p>\n<p>CERT-UA attributes the activity to UAC-0145, a threat cluster it tracks as a Sandworm sub-cluster. Public reporting indicates that UAC-0145 targeted Ukrainian users and organizations through several compromise methods.<\/p>\n<p>Investigators assessed at least ten websites associated with the ClickFix activity as compromised during June and July 2026.<\/p>\n<p>For enterprise security teams, the campaign demonstrates why endpoint protection, mobile device management, and user awareness must work together to reduce the risk of user-assisted attacks.<\/p>\n<h3>Incident at a Glance<\/h3>\n<table style=\"font-weight: 400; width: 99.437%;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"9\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td style=\"width: 39.3771%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Category<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 64.2937%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Details<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td style=\"width: 39.3771%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Threat cluster<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 64.2937%;\" data-celllook=\"0\"><span data-contrast=\"auto\">UAC-0145 (tracked by CERT-UA as a Sandworm sub-cluster)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td style=\"width: 39.3771%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Attack type<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 64.2937%;\" data-celllook=\"0\"><span data-contrast=\"auto\"><a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-social-engineering\/\">Social engineering<\/a> malware campaign<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td style=\"width: 39.3771%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Initial access<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 64.2937%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Fake ClickFix CAPTCHA prompts<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td style=\"width: 39.3771%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Primary targets<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 64.2937%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Ukrainian organizations<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td style=\"width: 39.3771%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Platforms targeted through separate attack paths<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 64.2937%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Windows through ClickFix prompts; Android through disguised APK files<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td style=\"width: 39.3771%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Windows malware<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 64.2937%;\" data-celllook=\"0\"><span data-contrast=\"auto\">GHETTOVIBE, SCOUTCURL, FLUIDLEECH, LOADLOOP, FREAKYPOLL<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td style=\"width: 39.3771%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Android malware<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 64.2937%;\" data-celllook=\"0\"><span data-contrast=\"auto\">COWARDDUCK<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td style=\"width: 39.3771%;\" data-celllook=\"0\"><span data-contrast=\"auto\">ClickFix findings publicly disclosed<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 64.2937%;\" data-celllook=\"0\"><span data-contrast=\"auto\">July 2026<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>How the ClickFix malware campaign worked<\/h2>\n<p>Unlike traditional malware campaigns that exploit software vulnerabilities, this attack relied on user-assisted execution.<\/p>\n<p>Compromised websites displayed fake <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-captcha-in-cyber-security\/\">CAPTCHA<\/a> instructions directing visitors to open a Windows terminal and paste a PowerShell command. CERT-UA found that one version of the command could download and save a VBS file in the Windows Startup autorun directory, enabling the script to run when the user signed in.<\/p>\n<p>Investigators observed the attackers using <code>Cloaking.House<\/code> to serve different content to different visitors and a custom tool called SMARTAXE to modify webpages dynamically and display CAPTCHA prompts based on visitor characteristics. The injected CAPTCHA content also used an EtherHiding technique to retrieve the domain name of a remote resource from an Ethereum smart contract.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/okobot-malware-150x150-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>OkoBot Malware Uses ClickFix and Fake GitHub Repositories<\/h4><p>Discover how attackers use ClickFix lures and fake GitHub repositories to distribute malware.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/okobot-malware-uses-clickfix-and-fake-github-repositories\/\" aria-label=\"OkoBot Malware Uses ClickFix and Fake GitHub Repositories\"><\/a><\/div><\/div><\/div>\n<h2>Windows malware chain<\/h2>\n<p>CERT-UA identified several malware families used during different stages of the campaign.<\/p>\n<table style=\"font-weight: 400; width: 98.8971%;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"6\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td style=\"width: 28.2116%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Malware<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 206.045%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Reported purpose<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td style=\"width: 28.2116%;\" data-celllook=\"0\"><span data-contrast=\"auto\">GHETTOVIBE<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 206.045%;\" data-celllook=\"0\"><span data-contrast=\"auto\">VBS payload used for persistence<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td style=\"width: 28.2116%;\" data-celllook=\"0\"><span data-contrast=\"auto\">SCOUTCURL<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 206.045%;\" data-celllook=\"0\"><span data-contrast=\"auto\">PowerShell reconnaissance script<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td style=\"width: 28.2116%;\" data-celllook=\"0\"><span data-contrast=\"auto\">FLUIDLEECH<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 206.045%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Loader disguised as antivirus software<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td style=\"width: 28.2116%;\" data-celllook=\"0\"><span data-contrast=\"auto\">LOADLOOP<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 206.045%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Malware loader<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td style=\"width: 28.2116%;\" data-celllook=\"0\"><span data-contrast=\"auto\">FREAKYPOLL<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 206.045%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Python backdoor<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Together, these components enabled reconnaissance, persistence, and the delivery of additional payloads. However, public reporting has not confirmed the complete objectives achieved during every intrusion.<\/p>\n<h2>How COWARDDUCK expanded the attack to Android devices<\/h2>\n<p>The campaign also included an Android backdoor known as COWARDDUCK, reportedly distributed as APK files masquerading as security tools through messaging applications.<\/p>\n<p>According to the published technical analysis, the malware can collect:<\/p>\n<ul>\n<li>Contacts<\/li>\n<li>Documents and archives<\/li>\n<li>Real-time geolocation<\/li>\n<\/ul>\n<p>It also communicates through legitimate cloud services, including the Dropbox API, which may help malicious traffic blend with normal network activity. There is no indication that Dropbox itself was compromised.<\/p>\n<p>This mobile component demonstrates how modern campaigns increasingly target both desktops and mobile devices, particularly in organizations that support BYOD or hybrid work environments.<\/p>\n<h2>Confirmed findings and remaining unknowns<\/h2>\n<h3>Confirmed<\/h3>\n<p>Public reporting and CERT-UA&#8217;s advisory indicate that:<\/p>\n<ul>\n<li>UAC-0145 used fake ClickFix CAPTCHA prompts as the initial lure.<\/li>\n<li>Victims were instructed to execute PowerShell commands manually.<\/li>\n<li>Multiple Windows malware families and the Android backdoor COWARDDUCK were identified.<\/li>\n<\/ul>\n<p>Investigators found that UAC-0145 targeted Ukrainian users and organizations, and they identified at least ten compromised websites linked to the ClickFix activity during June and July 2026.<\/p>\n<h3>Not publicly confirmed<\/h3>\n<p>At the time of writing, public reporting has not confirmed:<\/p>\n<ul>\n<li>The total number of affected organizations<\/li>\n<li>Large-scale data exfiltration<\/li>\n<li>Credential theft<\/li>\n<li>Ransomware deployment<\/li>\n<li>The attackers&#8217; full post-compromise objectives<\/li>\n<\/ul>\n<p>As the investigation continues, additional technical details may emerge.<\/p>\n<h2>Enterprise security lessons from the ClickFix malware attack<\/h2>\n<p>The campaign reinforces several important security lessons.<\/p>\n<ul>\n<li>Social engineering can bypass technical defenses by persuading users to execute malicious commands.<\/li>\n<li>PowerShell remains a common technique for malware delivery and post-exploitation activity.<\/li>\n<li>Mobile devices should be included in enterprise security strategies because attackers increasingly target Android alongside Windows.<\/li>\n<li>BYOD environments require consistent security policies across corporate and personally owned devices.<\/li>\n<li>Security awareness training should specifically cover fake CAPTCHA and ClickFix-style attacks.<\/li>\n<\/ul>\n<p>Organizations should also review controls around PowerShell usage, application installation, endpoint compliance, and mobile device governance to reduce exposure to similar campaigns.<\/p>\n<h2>How Hexnode helps reduce enterprise risk<\/h2>\n<p>While no platform can eliminate every social engineering attack, layered security controls can significantly reduce organizational risk.<\/p>\n<table style=\"font-weight: 400; width: 98.1381%;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"6\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td style=\"width: 34.7771%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Attack stage<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.5478%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Relevant Hexnode capability<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td style=\"width: 34.7771%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Unauthorized application installation<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.5478%;\" data-celllook=\"0\"><a href=\"https:\/\/www.hexnode.com\/uem\/\"><b><span data-contrast=\"auto\">Hexnode UEM<\/span><\/b><\/a><span data-contrast=\"auto\">\u00a0application management and policy enforcement<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td style=\"width: 34.7771%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Android device governance<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.5478%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Hexnode UEM<\/span><\/b><span data-contrast=\"auto\">\u00a0Android Enterprise and BYOD management<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td style=\"width: 34.7771%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Device compliance<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.5478%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Hexnode UEM<\/span><\/b><span data-contrast=\"auto\">\u00a0compliance policies and endpoint restrictions<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td style=\"width: 34.7771%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Endpoint investigation<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.5478%;\" data-celllook=\"0\"><a href=\"https:\/\/www.hexnode.com\/xdr\/\"><b><span data-contrast=\"auto\">Hexnode XDR<\/span><\/b><\/a><span data-contrast=\"auto\">\u00a0endpoint investigation and historical activity analysis<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td style=\"width: 34.7771%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Incident response<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 82.5478%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Hexnode XDR<\/span><\/b><span data-contrast=\"auto\">\u00a0process termination and device isolation<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>These capabilities can help organizations strengthen endpoint governance, investigate suspicious activity, and support incident response after a compromise.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck.webp?format=webp\" class=\"resource-box__image\" alt=\"Thumbnail-For-XDR-Intro-Deck\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck.webp?format=webp 1796w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-300x168.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1024x575.webp?format=webp 1024w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-768x431.webp?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1536x862.webp?format=webp 1536w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-178x100.webp?format=webp 178w\" sizes=\"auto, (max-width: 1796px) 100vw, 1796px\" title=\"Thumbnail-For-XDR-Intro-Deck\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Introduction to Hexnode XDR\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Learn how Hexnode XDR helps security teams detect, investigate, and respond to endpoint threats with unified visibility and response capabilities.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/introduction-to-hexnode-xdr\/'>\n                            Download the Presentation\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why are fake CAPTCHA attacks effective?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Fake CAPTCHA attacks exploit user trust rather than software vulnerabilities. By persuading users to execute commands themselves, attackers may evade some protections designed to block malicious links, attachments, or downloaded files. This technique also appears more legitimate because it mimics familiar verification steps.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Can ClickFix attacks affect managed enterprise devices?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Yes. Managed devices can still be affected if users manually execute malicious commands. However, organizations can reduce risk through application controls, endpoint policies, PowerShell restrictions where appropriate, and security awareness training.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why do attackers use legitimate cloud services like Dropbox?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Attackers sometimes use legitimate cloud platforms to transfer commands or stolen data because traffic to trusted services may blend with normal network activity. In this campaign, public reporting indicated that the Android malware communicated through the Dropbox API. There is no evidence that Dropbox itself was compromised.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How should organizations respond to ClickFix-style attacks?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Organizations should isolate affected devices, investigate PowerShell activity, identify persistence mechanisms, review endpoint and mobile device logs, and educate users about fake verification prompts. They should also reset credentials if compromise is suspected and follow their incident response procedures.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>The ClickFix malware campaign attributed to <a href=\"https:\/\/thehackernews.com\/2026\/07\/uac-0145-uses-clickfix-captchas-to.html?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=clickfix_malware\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">UAC-0145 demonstrates how modern attackers increasingly rely on social engineering instead of software exploits<\/a>.<\/p>\n<p>By using ClickFix and PowerShell against Windows devices while separately distributing malicious APK files to Android users, the activity highlights the need for coordinated endpoint and mobile security.<\/p>\n<p>Enterprises should treat ClickFix-style attacks as more than a phishing problem. Combining user education with device compliance, application management, endpoint investigation, and incident response can help reduce the impact of similar campaigns in the future.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Detect Threats Before They Become Breaches<\/h5><p>See how Hexnode XDR helps security teams investigate suspicious endpoint activity, accelerate incident response, and strengthen enterprise defenses.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign up now<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction The latest ClickFix malware campaign shows how attackers continue to exploit user trust instead&#8230;<\/p>\n","protected":false},"author":4,"featured_media":857,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,18],"class_list":["post-856","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-mobile","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ClickFix Malware Used in UAC-0145 Sandworm Campaign<\/title>\n<meta name=\"description\" content=\"Learn how UAC-0145 used ClickFix malware against Windows devices and separately distributed the COWARDDUCK Android backdoor.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ClickFix Malware Used in UAC-0145 Sandworm Campaign\" \/>\n<meta property=\"og:description\" content=\"Learn how UAC-0145 used ClickFix malware against Windows devices and separately distributed the COWARDDUCK Android backdoor.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-28T05:10:27+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T05:24:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/UAC-0145-Uses-ClickFix-Against-Windows-Devices-and-COWARDDUCK-Against-Android.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-malware-uac-0145-sandworm\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-malware-uac-0145-sandworm\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"UAC-0145 Uses ClickFix Against Windows Devices and COWARDDUCK Against Android\",\"datePublished\":\"2026-07-28T05:10:27+00:00\",\"dateModified\":\"2026-08-19T05:24:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-malware-uac-0145-sandworm\\\/\"},\"wordCount\":1104,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-malware-uac-0145-sandworm\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/UAC-0145-Uses-ClickFix-Against-Windows-Devices-and-COWARDDUCK-Against-Android.jpeg?format=webp\",\"articleSection\":[\"Malware\",\"Mobile\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-malware-uac-0145-sandworm\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-malware-uac-0145-sandworm\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-malware-uac-0145-sandworm\\\/\",\"name\":\"ClickFix Malware Used in UAC-0145 Sandworm Campaign\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-malware-uac-0145-sandworm\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-malware-uac-0145-sandworm\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/UAC-0145-Uses-ClickFix-Against-Windows-Devices-and-COWARDDUCK-Against-Android.jpeg?format=webp\",\"datePublished\":\"2026-07-28T05:10:27+00:00\",\"dateModified\":\"2026-08-19T05:24:55+00:00\",\"description\":\"Learn how UAC-0145 used ClickFix malware against Windows devices and separately distributed the COWARDDUCK Android backdoor.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-malware-uac-0145-sandworm\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-malware-uac-0145-sandworm\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-malware-uac-0145-sandworm\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/UAC-0145-Uses-ClickFix-Against-Windows-Devices-and-COWARDDUCK-Against-Android.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/UAC-0145-Uses-ClickFix-Against-Windows-Devices-and-COWARDDUCK-Against-Android.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"UAC-0145 Uses ClickFix Against Windows Devices and COWARDDUCK Against Android\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/clickfix-malware-uac-0145-sandworm\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"UAC-0145 Uses ClickFix Against Windows Devices and COWARDDUCK Against Android\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ClickFix Malware Used in UAC-0145 Sandworm Campaign","description":"Learn how UAC-0145 used ClickFix malware against Windows devices and separately distributed the COWARDDUCK Android backdoor.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/","og_locale":"en_US","og_type":"article","og_title":"ClickFix Malware Used in UAC-0145 Sandworm Campaign","og_description":"Learn how UAC-0145 used ClickFix malware against Windows devices and separately distributed the COWARDDUCK Android backdoor.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-07-28T05:10:27+00:00","article_modified_time":"2026-08-19T05:24:55+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/UAC-0145-Uses-ClickFix-Against-Windows-Devices-and-COWARDDUCK-Against-Android.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"UAC-0145 Uses ClickFix Against Windows Devices and COWARDDUCK Against Android","datePublished":"2026-07-28T05:10:27+00:00","dateModified":"2026-08-19T05:24:55+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/"},"wordCount":1104,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/UAC-0145-Uses-ClickFix-Against-Windows-Devices-and-COWARDDUCK-Against-Android.jpeg?format=webp","articleSection":["Malware","Mobile"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/","url":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/","name":"ClickFix Malware Used in UAC-0145 Sandworm Campaign","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/UAC-0145-Uses-ClickFix-Against-Windows-Devices-and-COWARDDUCK-Against-Android.jpeg?format=webp","datePublished":"2026-07-28T05:10:27+00:00","dateModified":"2026-08-19T05:24:55+00:00","description":"Learn how UAC-0145 used ClickFix malware against Windows devices and separately distributed the COWARDDUCK Android backdoor.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/UAC-0145-Uses-ClickFix-Against-Windows-Devices-and-COWARDDUCK-Against-Android.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/UAC-0145-Uses-ClickFix-Against-Windows-Devices-and-COWARDDUCK-Against-Android.jpeg?format=webp","width":1340,"height":754,"caption":"UAC-0145 Uses ClickFix Against Windows Devices and COWARDDUCK Against Android"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/clickfix-malware-uac-0145-sandworm\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"UAC-0145 Uses ClickFix Against Windows Devices and COWARDDUCK Against Android"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/856","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=856"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/856\/revisions"}],"predecessor-version":[{"id":860,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/856\/revisions\/860"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/857"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=856"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=856"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}