Advertisement
Advertisement
Advertisement
17 July 2026ยท5 min readยทBy Konrad Weber

Sandworm Hackers Using Clickfix to Infect Devices

Russian hacking group Sandworm is using the Clickfix technique to infect systems by tricking users into running scripts.

Sandworm Hackers Using Clickfix to Infect Devices

Clickfix is the latest weapon for Russian intelligence

Clickfix has moved. It's no longer just a tool for petty, financially motivated criminals, but now it's in the hands of Sandworm, one of the most sophisticated hacking units on the planet. And this notorious group, operating within the Russian military intelligence arm known as the GRU, is employing that deceptive technique to compromise devices belonging to sensitive organizations in Ukraine. The shift in tactics was identified throughout the spring and summer. It marks a notable evolution in how elite state-sponsored actors approach initial access.

How the deception works

Social engineering drives this entire operation. Hackers control websites that display a fake CAPTCHA to visitors, and the prompt claims you must copy a specific jumble of text and paste it into your terminal to prove you're human , but that text actually contains malicious scripts. So once you execute the command, you're unknowingly installing malware or opening a door for attackers to exfiltrate sensitive data from your machine. It's a dangerous trick.

flat screen computer monitor displaying white and black screen

Attackers are using several technical methods. They combine standard traffic filtering through services like Cloaking.House with a separate program code called SMARTAXE, and this tool lets them dynamically change a web page's content for the visitor. It's clever. But they also pull domain names from a smart contract to keep their infrastructure agile, so they can adapt quickly.

A library of malicious software

A target enters the script? The consequences are immediate. The campaign has already resulted in the network compromise of at least one organization after a device was infected with FreakyPoll, but this is just one of many custom packages in the Sandworm arsenal.

Market Context: According to IBM's 2024 Cost of a Data Breach Report, the global average cost of a data breach reached $4.88 million in 2024.
So the infection flow typically follows a predictable, destructive pattern.

  • Reconnaissance: Programs like SCOUTCURL gather basic device characteristics, installed software, and browser history.
  • Persistence: Scripts such as GHETTOVIBE are designed to save files in the Startup directory to maintain control after a reboot.
  • Expansion: Tools like FluidLeech, which masquerade as antivirus software, and LoadLoop are deployed to tighten the hacker's grip on the network.

The broader campaign against Ukraine

This specific technique isn't an isolated incident. Authorities discovered at least ten compromised websites displaying these PowerShell commands. But the goal is clear and simple: gain a foothold, determine the importance of the machine, and then pivot to deeper network infiltration, which follows a long history of Sandworm using creative, if sometimes crude, methods to trap their targets.

The command, as an example, could be intended to load and save a VBS file in the Startup directory. One of the variants of such a program was called GHETTOVIBE. At the next stage, in order to determine the importance of the cyberattack object, the SCOUTCURL software tool can be loaded onto the attacked computer, which is a PowerShell script that performs basic reconnaissance by collecting and exfiltrating information about the computer: basic characteristics, programs, files, Internet browser data, etc.

Shifting tactics beyond the browser

Sandworm doesn't rely on a single vector. That's a fact. This current wave of attacks highlights the effectiveness of tricking users into running commands, but the group remains active in other areas, and they've been tracked using lures to bait targets into installing apps that backdoor Android devices. But this specific threat, known as CowardDuck, assembles sensitive files and pushes them to a server controlled by the hackers.

They used to seed booby-trapped pirated software on Torrent trackers. Or they'd lure targets into long, drawn-out conversations over encrypted apps like Signal. But now they've borrowed tricks from the cybercriminal underground, and this shift proves that even the most elite units will adapt if it helps them bypass modern security hurdles. So administrators and hosting providers are being urged to keep a close watch for web shells and unauthorized extensions. Stop these incursions before they take hold.

Frequently Asked Questions

What is Clickfix and how is it being used by Sandworm?

Clickfix is a deceptive technique used by Sandworm, a Russian hacking unit within the GRU, to compromise devices. It involves tricking users into copying and pasting malicious text from a fake CAPTCHA into their terminal, which installs malware or opens a door for attackers.

How does the social engineering scheme behind Clickfix work?

The scheme uses websites displaying a fake CAPTCHA that claims you must copy a specific jumble of text and paste it into your terminal to prove you're human. However, that text contains malicious scripts, so executing the command unknowingly installs malware or allows attackers to exfiltrate sensitive data.

Why did Sandworm adopt Clickfix as a tactic?

Sandworm adopted Clickfix to bypass modern security hurdles, borrowing tricks from the cybercriminal underground. This shift proves that even elite state-sponsored units will adapt their methods to gain initial access more effectively.

When was the shift in Sandworm's tactics using Clickfix identified?

The shift in tactics was identified throughout the spring and summer. It marks a notable evolution in how elite state-sponsored actors approach initial access.

What are some of the malware tools used after a Clickfix infection?

After infection, tools like SCOUTCURL gather basic device characteristics and browser history for reconnaissance, while GHETTOVIBE saves files in the Startup directory for persistence. Other tools like FluidLeech and LoadLoop are deployed to tighten the hacker's grip on the network.

Konrad Weber
Written by
Infosec and Threats Writer

Konrad Weber writes about the security landscape, from emerging threats to the tools that guard against them. He is focused on helping readers understand risk in a connected world.

๐Ÿ’ฌ Comments (0)

Sign in to leave a comment.

No comments yet. Be the first!

Advertisement