UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware 42%

By Ravie Lakshmanan12%

7/19/2026, 6:30:00 AM

BS Summary: This article contains 17 faulty reasoning types, including Hasty Generalization, Representativeness Heuristic, and Negativity Bias, with Appeal to Authority as the most egregious example at 18.6% saturation with 91 hits. Analysis detected 728 faulty-reasoning hits from 489 analyzed words, generating a BS Score of 46.1% and a BS Rank of 42% (12,766 of 21,887 articles). This article is better (less manipulative) than 58.30% of the article peer group.

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. 
According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's primary foreign military intelligence agency. 
In these attacks, threat actors have been found to leverage fake CAPTCHA checks on compromised websites that instruct prospective targets to execute a PowerShell command in the terminal. 
"The mentioned command, as an example, could be intended for downloading and saving a VBS file in the Startup autorun directory; one of the variants of such a program was called GHETTOVIBE," CERT-UA said in an alert. 
The attacks also involve the use of SCOUTCURL, a PowerShell script that performs basic reconnaissance by harvesting details about the infected machine. 
Some of the other malicious programs found in the infected endpoints are as follows - 
FLUIDLEECH and LOADLOOP, which act as loaders, with the former masquerading as software for removing computer viruses. 
FREAKYPOLL, a Python backdoor 
At least 10 websites are assessed to have been compromised as part of this campaign between June and July 2026. 
Besides taking advantage of Cloaking.House, a traffic filtering service that makes it possible to serve different pages to different visitors, the attackers have been found to use a bespoke tool called SMARTAXE to dynamically alter the content of a web page depending on the site visitor and display a CAPTCHA check. 
The CAPTCHA content to be injected into the web page employs the EtherHiding technique to retrieve the domain name of the remote resource from an Ethereum smart contract using an address specified in the source code. 
CERT-UA said it also identified the threat actor using other attack techniques to break into devices, including backdooring Android devices by distributing APK files via messaging apps, by disguising them as security tools. 
The malware embedded in the APK file is a full-featured backdoor codenamed COWARDDUCK that can clandestinely collect the following details - 
Contacts 
Files matching certain extensions (".conf," ".json," ".ovpn," ".txt," ".doc," ".docx," ".xls," ".xlsx," ".pptx," ".zip," and ".rar") from the directories: "DCIM," "Documents," "Downloads," "Pictures," and "Alarms" 
Geolocation in real time 
In tandem, the malware uses the Dropbox cloud service API to upload files, while retrieving commands or data from an external server or from legitimate sites like steamcommunity[.]com. 
The use of ClickFix by the Kremlin-backed hacking crew marks a departure from prior campaigns that have made use of trojanized installers for Microsoft Windows or Office containing a built-in backdoor or through bogus antivirus software shared via the Signal messaging app. 
The disclosure comes as ClickFix continues to be an effective social engineering technique for malware delivery across the cyber threat landscape, with bad actors leveraging it to distribute OXLOADER, Mistic, SCMBANKER, ClickLock Stealer, TELEPUZ, and ACR Stealer. 
Article reasoning-pattern comparisonThis article: 0.0%Ravie Lakshmanan: 1.5%The Hacker News: 1.9%Confirmation Bias0.0%This article: 7.0%Ravie Lakshmanan: 1.4%The Hacker News: 1.2%Anchoring Bias7.0%This article: 7.6%Ravie Lakshmanan: 2.4%The Hacker News: 3.3%Availability Heuristic7.6%This article: 10.4%Ravie Lakshmanan: 1.7%The Hacker News: 1.5%Representativeness Heuristic10.4%This article: 0.0%Ravie Lakshmanan: 0.9%The Hacker News: 0.6%Hindsight Bias0.0%This article: 8.4%Ravie Lakshmanan: 2.4%The Hacker News: 2.5%Overconfidence Bias8.4%This article: 0.0%Ravie Lakshmanan: 2.4%The Hacker News: 2.7%Framing Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.8%The Hacker News: 1.0%Loss Aversion0.0%This article: 8.6%Ravie Lakshmanan: 0.4%The Hacker News: 0.6%Status Quo Bias8.6%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 0.0%Ravie Lakshmanan: 1.1%The Hacker News: 1.3%Optimism Bias0.0%This article: 0.0%Ravie Lakshmanan: 1.5%The Hacker News: 1.6%Pessimism Bias0.0%This article: 9.2%Ravie Lakshmanan: 7.7%The Hacker News: 6.7%Negativity Bias9.2%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.6%The Hacker News: 0.4%Fundamental Attribution Error0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Ravie Lakshmanan: 1.2%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 0.0%Ravie Lakshmanan: 2.4%The Hacker News: 1.5%Recency Bias0.0%This article: 6.7%Ravie Lakshmanan: 0.3%The Hacker News: 0.3%Primacy Effect6.7%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 18.6%Ravie Lakshmanan: 4.9%The Hacker News: 4.0%Appeal to Authority18.6%This article: 8.6%Ravie Lakshmanan: 0.5%The Hacker News: 1.6%False Dilemma8.6%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 0.5%Slippery Slope0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Circular Reasoning0.0%This article: 13.3%Ravie Lakshmanan: 4.0%The Hacker News: 4.3%Hasty Generalization13.3%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 7.6%Ravie Lakshmanan: 0.2%The Hacker News: 0.2%Bandwagon7.6%This article: 7.6%Ravie Lakshmanan: 1.1%The Hacker News: 1.1%Appeal to Emotion7.6%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.5%Begging the Question0.0%This article: 5.7%Ravie Lakshmanan: 2.1%The Hacker News: 1.9%Post Hoc (False Cause)5.7%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.0%Ravie Lakshmanan: 0.9%The Hacker News: 0.6%Burden of Proof0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.3%Composition/Division0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 1.0%Anecdotal0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%No True Scotsman0.0%This article: 7.0%Ravie Lakshmanan: 3.8%The Hacker News: 2.3%Ambiguity (Equivocation)7.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 7.6%Ravie Lakshmanan: 3.4%The Hacker News: 1.4%Unattributed Quote7.6%This article: 7.6%Ravie Lakshmanan: 2.6%The Hacker News: 0.9%Quote-first Misdirection7.6%This article: 7.6%Ravie Lakshmanan: 2.5%The Hacker News: 2.3%Biased Writer Voice7.6%This article: 0.0%Ravie Lakshmanan: 2.4%The Hacker News: 4.4%Indoctrination0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 3.0%Attempt to Sell a Product or S…0.0%

489 words analyzed.

Speakers

1speaker21%attributed speech385writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 10 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageComputer Emergency Response Team of Ukraine (CERT-UA) • 34 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageComputer Emergency Response Team of Ukraine (CERT-UA) • 37 words • 100.0% coverageWriter's voice • 22 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 51 words • 0.0% coverageWriter's voice • 36 words • 0.0% coverageComputer Emergency Response Team of Ukraine (CERT-UA) • 33 words • 0.0% coverageWriter's voice • 21 words • 0.0% coverageWriter's voice • 1 words • 0.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 4 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 42 words • 0.0% coverageWriter's voice • 37 words • 100.0% coverage
100%flagged-word coverage
104 attributed words100% of attributed speech78% writer coverage
0%20.0%40.0%Unattributed Quote+35.6 ptsWriter: 0.0%Computer Emergency Response Team of Ukraine (CERT-UA): 35.6%35.6%Quote-first Misdirection+35.6 ptsWriter: 0.0%Computer Emergency Response Team of Ukraine (CERT-UA): 35.6%35.6%Biased Writer Voice-9.6 ptsWriter: 9.6%Computer Emergency Response Team of Ukraine (CERT-UA): 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.