CERT-UA says Russia’s Sandworm is using fake CAPTCHA prompts to trick Ukrainians into running PowerShell malware

Ukraine’s cyber agency says Russian military hackers are using fake CAPTCHA checks on compromised websites to trick Ukrainian targets into infecting their own Windows PCs. CERT-UA said Sandworm has increasingly used the ClickFix social-engineering technique in June and July 2026, directing victims to paste PowerShell commands that install malware including GhettoVibe, ScoutCurl, FluidLeech, and LoadLoop; the agency also said the group continues related Android lures and Signal-based social engineering.
Why it matters: This is an active intrusion method aimed at Ukrainian users, including government and military-linked targets, and it can lead to persistent compromise and follow-on destructive attacks. Organizations and individuals in Ukraine should treat CAPTCHA pages asking them to paste commands as malicious, block PowerShell abuse where possible, and warn staff about Signal and fake security-tool lures.

Sources

Sandworm hackers have a CAPTCHA trick for Ukrainians
2026.07.16 100% relevant
This article establishes a distinct new campaign update from CERT-UA describing Sandworm’s current initial-access technique, named malware, and targeting pattern rather than updating a previously tracked identical event.
← Back to all stories