CERT-UA reported that the Russia-linked Sandworm cluster UAC-0145, tied to UAC-0002 and also tracked as APT44 and Seashell Blizzard, has run a sustained campaign against Ukrainian targets using several social-engineering and malware-delivery methods. Investigators said attackers compromised more than 10 websites and deployed ClickFix-style fake CAPTCHA pages that instructed visitors to paste malicious PowerShell commands into Windows, while other lures included trojanized software installers from torrent trackers, bogus antivirus installation requests sent through Signal, and a fake Android security app. CERT-UA linked the activity to long-running operations targeting Ukrainian government and military-related organizations.
The campaign used a broad malware ecosystem including GHETTOVIBE, SCOUTCURL, FLUIDLEECH, LOADLOOP, FREAKYPOLL, SMARTAXE, and the Android backdoor COWARDDUCK, alongside legitimate tools such as OpenSSH, Tor, and rsync for persistence, tunneling, and exfiltration. CERT-UA said at least one infection delivered through a trojanized installer enabled persistence and lateral movement inside an organization and was later used in a destructive attack against the infrastructure of a central executive authority of Ukraine. Analysts also found the operators using Cloaking.House and blockchain eth_call lookups to retrieve remote domains dynamically, while the Android malware was capable of stealing files, contacts, device data, and real-time geolocation and used the Dropbox API and content from legitimate services in its command-and-control workflow.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On July 15, 2026, CERT-UA published a report describing a sustained cyber threat campaign targeting Ukraine and attributed it to cluster UAC-0145, a subcluster of UAC-0002 also known as Sandworm, APT44, and Seashell Blizzard. The report detailed multiple initial access vectors and a malware ecosystem including GHETTOVIBE, SCOUTCURL, FLUIDLEECH, LOADLOOP, FREAKYPOLL, SMARTAXE, and COWARDDUCK.
During June and July, CERT-UA analyzed ClickFix activity across more than ten compromised web resources. The agency said the attackers used Cloaking.House and SMARTAXE, including blockchain smart-contract lookups via eth_call to dynamically retrieve remote domains.
CERT-UA reported that during spring and summer, Sandworm increasingly used ClickFix-style fake CAPTCHA prompts on compromised websites to trick victims into pasting malicious PowerShell commands into Windows systems. The activity was tied to malware including GhettoVibe, ScoutCurl, FluidLeech, and LoadLoop.
CERT-UA reported that the campaign also used social engineering via Signal and other messaging apps, with attackers posing as providers of antivirus or security software to deliver malware. This was identified as another initial access vector alongside trojanized installers and ClickFix pages.
CERT-UA said the attackers distributed the Android backdoor COWARDDUCK as a fake protective APK. The malware could steal device data, files, contacts, and real-time geolocation, and used Dropbox API and content from legitimate services in its command and exfiltration workflow.
CERT-UA reported that at least one infection obtained through trojanized software installers from torrent trackers was later used for persistence and lateral movement inside an organization, enabling a destructive cyberattack against the infrastructure of a central executive authority of Ukraine. The campaign was attributed to cluster UAC-0145, a subcluster of UAC-0002/Sandworm.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
trojan-killer.net
Open sourcethehackernews.com
Open sourcescworld.com
Open sourcearstechnica.com
Open sourcetherecord.media
Open sourcecert.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.