UAC-0145: The Dangerous Hack Using ClickFix to Infect Systems
The group linked to Sandworm is employing social engineering tactics via fake CAPTCHAs to deploy data-stealing malware in Ukraine.

The Evolution of Deception: ClickFix as an Attack Vector
The cybersecurity landscape has been shaken once again by the activities of the group UAC-0145, an operational cell linked to the infamous Sandworm unit of the Russian GRU. According to recent reports from CERT-UA, these actors are using a technique known as ClickFix to compromise devices in Ukraine by directly deceiving users.
This hack strategy does not exploit a traditional technical vulnerability in software; instead, it exploits user trust. Through fake error windows that simulate CAPTCHAs, attackers trick victims into copying and executing malicious commands on their systems under the guise of "fixing" a display or connection error.
How Does UAC-0145 Malware Operate?
The tactic is deceptively simple yet highly effective. When attempting to access a website, the user is presented with a message stating that their browser cannot process the content correctly. To "resolve" this, they are instructed to open the Windows command prompt and paste a script provided by the attacker.
"The use of social engineering tactics remains the fastest way for attackers to gain initial access, often bypassing the most robust perimeter defenses," note threat intelligence experts.
Once executed, the code enables the download of malware specialized in stealing data and credentials. Although the primary goal in this campaign has been espionage, the ability of these groups to escalate attacks is a constant concern, recalling past cases where ransomware tools have been deployed to cause massive damage to critical infrastructure—a topic we have previously analyzed in depth when exploring Confusión en Armenia: ¿Detención errónea de un hacker del grupo REvil?.
Recommended Protection Measures
To mitigate the risks derived from this campaign, it is essential to implement the following measures:
- Education and awareness: Instruct users on the risks of executing unknown commands in the terminal.
- Privilege restriction: Limit access to administrative tools such as
PowerShellorcmdfor standard users. - Network monitoring: Detect unusual connections to command and control (C2) servers that typically accompany these types of intrusions.
Modern cybersecurity is won at the intersection of technology and human behavior. The sophistication of UAC-0145 demonstrates that, no matter how well-patched our systems are against a zero-day vulnerability, the weakest link will always be human interaction. Staying alert to unexpected messages that request technical actions is the best defense against the growing threat of state-sponsored cybercrime.
Sources:
Related articles
7 de septiembre de 2026
Cybersecurity: New ScreenConnect vulnerability facilitates attacks
Researchers have detected a four-stage infection chain that uses ScreenConnect to compromise systems through malicious scripts.
30 de agosto de 2026
Breach at Manchester Airports Group: The hack exposing 86 GB of data
The group FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group, revealing sensitive passenger and booking information.
23 de agosto de 2026
Hackers infect Android car systems: the new vulnerability
A supply chain attack is turning Android-based automotive multimedia systems into part of a botnet, putting driver security at risk.
16 de agosto de 2026
AmnesiaStealer: The new hack compromising macOS security
We analyze AmnesiaStealer, a macOS malware that enables remote browser control and puts user privacy at risk.
Loading comments...