Now, even Russia's most elite hackers are using Clickfix to infect devices

Ars Technica News

Summary

Russian state-sponsored hacking group Sandworm has adopted the Clickfix attack technique to compromise devices in Ukraine, using fake CAPTCHAs to trick users into running malicious PowerShell scripts.

<p>One of the Russian government’s most elite hacking groups has adopted an attack, known as Clickfix, to compromise devices belonging to sensitive organizations in Ukraine, the latter country’s CERT center is warning.</p> <p><a href="https://arstechnica.com/security/2025/11/clickfix-may-be-the-biggest-security-threat-your-family-has-never-heard-of/">Clickfix</a> has emerged as an effective attack technique that attackers, primarily financially motivated criminals, began using in the last year or so. Websites under the control of the attackers display a CAPTCHA that requires the visitor to copy a jumble of text and paste it into the terminal. The text contains scripts that, once entered, perform malicious actions, typically by installing malware or exfiltrating sensitive data. Ukraine’s CERT <a href="https://cert.gov.ua/article/6318437">said</a> Wednesday that <a href="https://www.wired.com/story/sandworm-kremlin-most-dangerous-hackers/">Sandworm</a>, an advanced hacking unit inside the GRU, Russia’s military intelligence arm, is now using the technique.</p> <h2>"GhettoVibe," "ScoutCurl," and many more</h2> <p>The Clickfix attacks began in the spring and have continued through the summer. The campaign has resulted in the network compromise of at least one organization when a connected device was found to be infected by FreakyPoll, the name of one of Sandworm’s custom malware packages. Ukrainian authorities discovered 10 compromised websites that displayed a PowerShell command as part of a fake CAPTCHA that said it had to be passed to ensure a real human was behind the visiting device’s keyboard.</p><p><a href="https://arstechnica.com/security/2026/07/now-even-russias-most-elite-hackers-are-using-clickfix-to-infect-devices/">Read full article</a></p> <p><a href="https://arstechnica.com/security/2026/07/now-even-russias-most-elite-hackers-are-using-clickfix-to-infect-devices/#comments">Comments</a></p>
Original Article
View Cached Full Text

Cached at: 07/16/26, 10:54 PM

# Now, even Russia's most elite hackers are using Clickfix to infect devices Source: [https://arstechnica.com/security/2026/07/now-even-russias-most-elite-hackers-are-using-clickfix-to-infect-devices/](https://arstechnica.com/security/2026/07/now-even-russias-most-elite-hackers-are-using-clickfix-to-infect-devices/) One of the Russian government’s most elite hacking groups has adopted an attack, known as Clickfix, to compromise devices belonging to sensitive organizations in Ukraine, the latter country’s CERT center is warning\. [Clickfix](https://arstechnica.com/security/2025/11/clickfix-may-be-the-biggest-security-threat-your-family-has-never-heard-of/)has emerged as an effective attack technique that attackers, primarily financially motivated criminals, began using in the last year or so\. Websites under the control of the attackers display a CAPTCHA that requires the visitor to copy a jumble of text and paste it into the terminal\. The text contains scripts that, once entered, perform malicious actions, typically by installing malware or exfiltrating sensitive data\. Ukraine’s CERT[said](https://cert.gov.ua/article/6318437)Wednesday that[Sandworm](https://www.wired.com/story/sandworm-kremlin-most-dangerous-hackers/), an advanced hacking unit inside the GRU, Russia’s military intelligence arm, is now using the technique\. ## “GhettoVibe,” “ScoutCurl,” and many more The Clickfix attacks began in the spring and have continued through the summer\. The campaign has resulted in the network compromise of at least one organization when a connected device was found to be infected by FreakyPoll, the name of one of Sandworm’s custom malware packages\. Ukrainian authorities discovered 10 compromised websites that displayed a PowerShell command as part of a fake CAPTCHA that said it had to be passed to ensure a real human was behind the visiting device’s keyboard\. Once the user entered the script, it could install malicious Visual Basic scripts and other malicious wares that went on to install a variety of Sandworm malware\. Typically, the first malware to run was a reconnaissance program that gathered information from the infected device\. Machines deemed important would then receive follow\-on malware that backdoored the system\. “The command, as an example, could be intended to load and save a VBS file in the Startup directory,” a translated version of Tuesday’s advisory stated\. “One of the variants of such a program was called GHETTOVIBE\. At the next stage, in order to determine the importance of the cyberattack object, the SCOUTCURL software tool can be loaded onto the attacked computer, which is a PowerShell script that performs basic reconnaissance by collecting and exfiltrating information about the computer: basic characteristics, programs, files, Internet browser data, etc\.”

Similar Articles

Russia Hacked Routers to Steal Microsoft Office Tokens

Krebs on Security

Russian state-backed hackers (Forest Blizzard/APT28) used known vulnerabilities in old routers to hijack DNS settings and steal OAuth authentication tokens from Microsoft Office users, compromising over 200 organizations and 5,000 consumer devices without deploying malware.

‘CanisterWorm’ Springs Wiper Attack Targeting Iran

Krebs on Security

A financially motivated cybercrime group known as TeamPCP has deployed a self-propagating wiper worm, CanisterWorm, that targets systems in Iran by wiping data on compromised cloud infrastructure and local machines, following a supply chain attack on the Trivy vulnerability scanner.