Ukraine's CERT has warned that Sandworm, a top-tier Russian GRU hacking group, has adopted the 'Clickfix' social engineering technique to compromise devices in Ukraine. This method involves tricking users into pasting malicious PowerShell commands disguised as CAPTCHA checks, leading to the installation of Sandworm's custom malware like FreakyPoll.
Background
Sandworm is widely recognized as one of the most sophisticated state-sponsored threat actors, previously responsible for major incidents like the NotPetya ransomware attack. The shift towards Clickfix indicates a trend where advanced persistent threats (APTs) adopt simpler, high-volume social engineering tactics to lower the barrier for initial access.
- Source
- Ars Technica
- Published
- Jul 17, 2026 at 03:28 AM
- Score
- 8.0 / 10