Russian state-sponsored hacking group Sandworm has adopted the Clickfix attack technique to compromise devices in Ukraine, using fake CAPTCHAs to trick users into running malicious PowerShell scripts.
<p>One of the Russian government’s most elite hacking groups has adopted an attack, known as Clickfix, to compromise devices belonging to sensitive organizations in Ukraine, the latter country’s CERT center is warning.</p>
<p><a href="https://arstechnica.com/security/2025/11/clickfix-may-be-the-biggest-security-threat-your-family-has-never-heard-of/">Clickfix</a> has emerged as an effective attack technique that attackers, primarily financially motivated criminals, began using in the last year or so. Websites under the control of the attackers display a CAPTCHA that requires the visitor to copy a jumble of text and paste it into the terminal. The text contains scripts that, once entered, perform malicious actions, typically by installing malware or exfiltrating sensitive data. Ukraine’s CERT <a href="https://cert.gov.ua/article/6318437">said</a> Wednesday that <a href="https://www.wired.com/story/sandworm-kremlin-most-dangerous-hackers/">Sandworm</a>, an advanced hacking unit inside the GRU, Russia’s military intelligence arm, is now using the technique.</p>
<h2>"GhettoVibe," "ScoutCurl," and many more</h2>
<p>The Clickfix attacks began in the spring and have continued through the summer. The campaign has resulted in the network compromise of at least one organization when a connected device was found to be infected by FreakyPoll, the name of one of Sandworm’s custom malware packages. Ukrainian authorities discovered 10 compromised websites that displayed a PowerShell command as part of a fake CAPTCHA that said it had to be passed to ensure a real human was behind the visiting device’s keyboard.</p><p><a href="https://arstechnica.com/security/2026/07/now-even-russias-most-elite-hackers-are-using-clickfix-to-infect-devices/">Read full article</a></p>
<p><a href="https://arstechnica.com/security/2026/07/now-even-russias-most-elite-hackers-are-using-clickfix-to-infect-devices/#comments">Comments</a></p>
# Now, even Russia's most elite hackers are using Clickfix to infect devices
Source: [https://arstechnica.com/security/2026/07/now-even-russias-most-elite-hackers-are-using-clickfix-to-infect-devices/](https://arstechnica.com/security/2026/07/now-even-russias-most-elite-hackers-are-using-clickfix-to-infect-devices/)
One of the Russian government’s most elite hacking groups has adopted an attack, known as Clickfix, to compromise devices belonging to sensitive organizations in Ukraine, the latter country’s CERT center is warning\.
[Clickfix](https://arstechnica.com/security/2025/11/clickfix-may-be-the-biggest-security-threat-your-family-has-never-heard-of/)has emerged as an effective attack technique that attackers, primarily financially motivated criminals, began using in the last year or so\. Websites under the control of the attackers display a CAPTCHA that requires the visitor to copy a jumble of text and paste it into the terminal\. The text contains scripts that, once entered, perform malicious actions, typically by installing malware or exfiltrating sensitive data\. Ukraine’s CERT[said](https://cert.gov.ua/article/6318437)Wednesday that[Sandworm](https://www.wired.com/story/sandworm-kremlin-most-dangerous-hackers/), an advanced hacking unit inside the GRU, Russia’s military intelligence arm, is now using the technique\.
## “GhettoVibe,” “ScoutCurl,” and many more
The Clickfix attacks began in the spring and have continued through the summer\. The campaign has resulted in the network compromise of at least one organization when a connected device was found to be infected by FreakyPoll, the name of one of Sandworm’s custom malware packages\. Ukrainian authorities discovered 10 compromised websites that displayed a PowerShell command as part of a fake CAPTCHA that said it had to be passed to ensure a real human was behind the visiting device’s keyboard\.
Once the user entered the script, it could install malicious Visual Basic scripts and other malicious wares that went on to install a variety of Sandworm malware\. Typically, the first malware to run was a reconnaissance program that gathered information from the infected device\. Machines deemed important would then receive follow\-on malware that backdoored the system\.
“The command, as an example, could be intended to load and save a VBS file in the Startup directory,” a translated version of Tuesday’s advisory stated\. “One of the variants of such a program was called GHETTOVIBE\. At the next stage, in order to determine the importance of the cyberattack object, the SCOUTCURL software tool can be loaded onto the attacked computer, which is a PowerShell script that performs basic reconnaissance by collecting and exfiltrating information about the computer: basic characteristics, programs, files, Internet browser data, etc\.”
Russian state-backed hackers (Forest Blizzard/APT28) used known vulnerabilities in old routers to hijack DNS settings and steal OAuth authentication tokens from Microsoft Office users, compromising over 200 organizations and 5,000 consumer devices without deploying malware.
CrowdStrike has discovered a worm that targets AI software supply chains, stealing credentials and performing destructive actions while evading detection by mimicking legitimate AI coding activities.
Researchers have devised a pull-based prompt injection attack called HalluSquatting that exploits AI coding assistants' tendency to hallucinate resource identifiers, enabling the assembly of massive botnets and large-scale attacks.
A financially motivated cybercrime group known as TeamPCP has deployed a self-propagating wiper worm, CanisterWorm, that targets systems in Iran by wiping data on compromised cloud infrastructure and local machines, following a supply chain attack on the Trivy vulnerability scanner.
The US government warns that Russian state hackers are targeting poorly configured home and small office routers to build botnets for cyber attacks against critical infrastructure, with CISA issuing a joint advisory.