E-Ink News Daily

Back to list

Now, even Russia's most elite hackers are using Clickfix to infect devices

Ukraine's CERT has warned that Sandworm, a top-tier Russian GRU hacking group, has adopted the 'Clickfix' social engineering technique to compromise devices in Ukraine. This method involves tricking users into pasting malicious PowerShell commands disguised as CAPTCHA checks, leading to the installation of Sandworm's custom malware like FreakyPoll.

Background

Sandworm is widely recognized as one of the most sophisticated state-sponsored threat actors, previously responsible for major incidents like the NotPetya ransomware attack. The shift towards Clickfix indicates a trend where advanced persistent threats (APTs) adopt simpler, high-volume social engineering tactics to lower the barrier for initial access.

Source
Ars Technica
Published
Jul 17, 2026 at 03:28 AM
Score
8.0 / 10