CERT-UA warned that the Russian state-linked Sandworm group has adopted the ClickFix social-engineering technique to target Ukrainian organizations, using compromised websites and fake CAPTCHA pages that trick users into copying and pasting malicious PowerShell commands. Those commands reportedly download and execute multiple payloads, including FreakyPoll, GHETTOVIBE, SCOUTCURL, FluidLeech, and LoadLoop, while Sandworm also used a custom utility called SMARTAXE to support the CAPTCHA-hosting infrastructure by querying Ethereum smart contracts for domain lists. CERT-UA said the activity began in spring 2026 and continued through summer, with at least ten sites identified as hosting the malicious lure infrastructure.
The campaign reflects a broader surge in ClickFix and related copy-and-paste attack variants such as CrashFix, InstallFix, and FileFix, which security researchers say are increasingly used for initial access and malware delivery. Huntress reported a sharp rise in ClickFix incidents, while other documented cases have shown attackers chaining fake browser extensions, obfuscated PowerShell, finger.exe, Python-based remote access tools, persistence via Run keys and scheduled tasks, and staged payload downloads. Defenders were urged to look beyond the lure pages and hunt for compromised web servers, web shells, unauthorized CAPTCHA content, suspicious process chains, dropped files, persistence artifacts, and outbound connections tied to follow-on malware activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
JFrog reported in March 2026 that a malicious npm package posing as OpenClaw used a postinstall hook, fake installer prompts, password harvesting, and a second-stage payload fetched from trackpipe[.]dev.
Microsoft reported a February 2026 ClickFix-style campaign dubbed CrashFix in which a fake browser extension led victims to run obfuscated PowerShell, abuse finger.exe, deploy WinPython and a Python RAT, and establish persistence via Run keys and scheduled tasks.
CERT-UA said Sandworm's ClickFix activity continued through summer 2026, with at least ten websites identified as hosting malicious CAPTCHA infrastructure and payload delivery for malware including FreakyPoll, GHETTOVIBE, SCOUTCURL, FluidLeech, and LoadLoop.
CERT-UA said the Russian APT group Sandworm started using the ClickFix social engineering technique in spring 2026 to target devices of interest in Ukraine via malicious CAPTCHA pages that trick users into pasting PowerShell commands.
Huntress reported a 631% increase in ClickFix-related incidents, highlighting the growing prevalence of copy-and-paste social engineering attacks.
CERT-UA warned that Sandworm was using ClickFix against Ukrainian organizations and described SMARTAXE, a custom tool that queried Ethereum smart contracts for domain lists to support the CAPTCHA-hosting infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcepentestpartners.com
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.