Russian Military Hackers Trick Ukrainians Into Infecting Their Own PCs

Ukraine's cyber emergency team says a Sandworm sub-group is using fake CAPTCHA prompts to plant data-stealing malware.

ThreatVectr Newsdesk· 3 min read
Full-frame 16:9 photoreal editorial shot of a laptop screen in a dim office, showing a generic fake verification prompt with a highlighted keyboard shortcut ins
Share

Key points

  • Ukraine's Computer Emergency Response Team (CERT-UA) has linked a new malware campaign to UAC-0145, a sub-group inside the Russian military hacking unit known as Sandworm.
  • Sandworm is run by the GRU, Russia's military intelligence agency.
  • The attackers use a trick called ClickFix, where a fake CAPTCHA on a webpage persuades the victim to paste and run a malicious command themselves.
  • The end goal is to install information-stealing malware, software designed to quietly copy passwords, files and browser data off the machine.

Ukraine's national cyber emergency team has caught Russian military hackers pulling an old trick on a new set of victims.

The technique is called ClickFix. It is one of the more depressing things happening in security right now, because it does not exploit a clever software bug. It exploits the user.

Here is how it works in practice. You land on a webpage. It shows what looks like a normal CAPTCHA, one of those "prove you are human" puzzles. Instead of clicking pictures of traffic lights, the page tells you to press Windows+R, paste a line of text, and hit Enter. People do it. And the line of text is a command that downloads malware onto their own computer.

The failure mode here is that the attack skips every antivirus and email filter you have, because the person at the keyboard is the one running the code.

Who is behind this campaign?

The attackers are a sub-group known as UAC-0145, which sits inside Sandworm. Sandworm is one of the most notorious hacking units on the planet, run by the GRU, Russia's military intelligence service. The Computer Emergency Response Team of Ukraine (CERT-UA) attributed the activity, as first reported by The Hacker News.

Sandworm's greatest hits are not subtle. This is the same broad outfit tied to the NotPetya wiper in 2017 and to attacks on Ukraine's power grid. Info-stealers on individual laptops sound quieter than that, but stolen credentials are how the bigger intrusions start. One thing the post-mortem will say, again, is that the initial foothold was a browser session and a copy-paste.

What is the malware actually doing?

CERT-UA describes the payload as an information stealer. In plain terms, that is a program that rifles through the machine for anything sellable or useful: saved browser passwords, session cookies that let an attacker log in as you without needing the password, cryptocurrency wallets, documents, and screenshots.

For a Ukrainian target, the risk is not just financial. Stolen session cookies from a government or defence worker's browser can hand Russian intelligence access to internal systems without triggering a single login alert.

What should ordinary people do?

If a website ever asks you to open the Windows Run box, or to paste something into PowerShell or Terminal, close the tab. No legitimate CAPTCHA works that way. No real IT helpdesk asks you to do it out of the blue either.

The campaign is aimed at Ukrainian targets, but ClickFix pages have been popping up worldwide for over a year, pushed by criminal groups as well as state ones. It works on English-speaking office workers just as well as Ukrainian ones.

If you think you already followed one of these instructions, assume the passwords saved in your browser are gone. Change them from a different device. Log out of everything, which invalidates the stolen cookies. Then run a full scan.

Operational takeaway: the browser is now the endpoint, and the human clicking around inside it is the security control that failed first.

© 2026 Threat Vectr