CERT-UA Names Sandworm Subgroup UAC-0145 Behind ClickFix CAPTCHA Campaign Against Ukrainian Devices

CERT-UA names UAC-0145 as the Sandworm sub-cluster behind the ClickFix CAPTCHA activity against Ukrainian devices - a GRU-affiliated crew, and defender awareness for Ukraine-adjacent teams this weekend.

Share
Editorial illustration of a fake CAPTCHA checkbox tagged with a state emblem over a map of Ukraine, marking CERT-UA naming Sandworm subgroup UAC-0145.

Key Takeaways

  • CERT-UA named UAC-0145, a sub-cluster it places within Sandworm and affiliated with Russia's Main Intelligence Directorate (GRU), as the actor behind a ClickFix CAPTCHA campaign infecting Ukrainian devices with data-stealing malware.
  • According to CERT-UA as reported by The Hacker News, at least 10 websites were compromised between June and July 2026 to serve fake CAPTCHA checks, and the alert enumerates named Windows families alongside an Android backdoor delivered as a disguised security app.
  • For defenders supporting Ukraine-adjacent organizations, the naming reinforces that a fake "verify" or "fix" prompt can front state-aligned activity - so end-user guidance to refuse manual on-device instructions is the durable control, not a new indicator.

CERT-UA puts a name - UAC-0145 - and a GRU affiliation on the Sandworm ClickFix activity; defender awareness for Ukraine-adjacent teams this weekend.

KYIV — Ukraine's national computer emergency response team, CERT-UA, has attributed an ongoing ClickFix CAPTCHA campaign against Ukrainian devices to UAC-0145, a sub-cluster it places within Sandworm - the intrusion set affiliated with the Main Intelligence Directorate (GRU), Russia's military intelligence service. The attribution, reported on July 19, 2026 and drawn from a CERT-UA alert, gives a name and a state affiliation to activity that defenders in and around Ukraine have been watching take shape.

This article summarizes what CERT-UA documented and situates the naming against the Sandworm and ClickFix threads The CyberSignal has tracked. In keeping with our defender-first framing, it does not reproduce how the lure operates; the load-bearing points here are the attribution, the scope CERT-UA describes, and what the sub-cluster naming means for teams that support Ukraine-adjacent work.

At a Glance
FieldDetails
Attributed byCERT-UA
Date reportedJuly 19, 2026
Sub-clusterUAC-0145 (within Sandworm)
AffiliationMain Intelligence Directorate (GRU)
TechniqueClickFix via fake CAPTCHA checks
Scope (reported)At least 10 compromised websites, June-July 2026
TargetsUkrainian devices (Windows and Android)

What CERT-UA Documented

According to a CERT-UA alert, as reported by The Hacker News, the ClickFix CAPTCHA activity against Ukrainian devices has been attributed to UAC-0145, characterized as a sub-cluster within Sandworm - the intrusion set affiliated with the GRU. The campaign relies on fake CAPTCHA checks placed on compromised websites that steer Ukrainian users toward infecting their own machines with data-stealing malware. We are naming what CERT-UA named and attributing the reporting rather than walking through the mechanics of the lure.

CERT-UA assessed that at least 10 websites were compromised between June and July 2026 to serve the fake CAPTCHA content. The alert enumerates several named Windows programs - including loader components and a Python backdoor - and describes an Android backdoor, tracked as COWARDDUCK, distributed as APK files disguised as security tools through messaging apps. That level of detail is worth flagging against our earlier tracking: where the specific data-stealing payload had been unconfirmed in prior coverage, CERT-UA's alert now supplies named families and bounds the scope to roughly 10 sites, though a total count of infected devices is not given.

The defensive core of the disclosure is the attribution and the scope, not a technique walkthrough. A state-affiliated cluster is now formally named behind a lure family that many teams had mentally filed under commodity crimeware, and that reclassification - rather than any single indicator - is the part worth acting on.

Continuation Context: Briefs #218 and #237

This naming does not arrive in isolation; it continues a thread The CyberSignal has been following. In Brief #218 we covered a Sandworm CAPTCHA-and-PowerShell operation aimed at Ukrainian targets, and whether today's UAC-0145 activity is the same operation under a new label or a distinct one is not settled by the attribution alone.

In Brief #237 we summarized an Ars Technica report that Russia's Sandworm cluster had adopted ClickFix - a technique the outlet tied historically to financially motivated crime. CERT-UA's alert now supplies what that report left open: a specific sub-cluster name and a GRU affiliation. Sandworm's broader activity has also surfaced in vendor telemetry, including the ESET APT report covering Sandworm and adjacent clusters. Seen together, the UAC-0145 naming is the next data point in a technique steadily diffusing across the actor spectrum, not a bolt from the blue.

The UAC-0145 Sub-Cluster and GRU-Affiliation Framing

CERT-UA's language treats UAC-0145 as a tracked sub-cluster within Sandworm rather than a new independent actor. That distinction matters for defenders: it ties the activity to a known, well-resourced lineage while acknowledging that CERT-UA is scoping a specific tranche of operations under its own designator. Any characterization of Sandworm as among Russia's most capable operators is reporting-and-agency framing, and we present it as such rather than as an independent CyberSignal ranking.

The affiliation is the reprioritizing detail. A GRU-linked cluster reaching for a fake-CAPTCHA lure is a reminder that attribution and technique are separate axes - Russia-linked operators have repeatedly used whatever works, from opportunistic file-format flaws, as in the WinRAR weakness exploited by Russia-aligned groups against Ukrainian targets, to consumer-messaging phishing, as when Germany publicly blamed Russia for Signal phishing aimed at lawmakers. The reporting notes the ClickFix use marks a departure from prior campaigns that leaned on trojanized installers or fake antivirus software shared through the Signal app - the same actor swapping delivery methods rather than acquiring a new capability.

Defender-Team End-User Awareness for Ukraine-Adjacent Organizations

The end-user lesson is behavioral and deliberately generic - cataloging a specific command or key sequence would teach the technique more than it would defend against it. The durable guidance is that a web page asking a person to carry out manual steps on their own computer to "verify," "fix," or "continue" is a pattern to stop and question, regardless of how legitimate the surrounding page looks. That advice held when the technique was treated as commodity crime, and it holds now that a GRU-affiliated cluster has been named behind it.

For awareness programs, the framing shift is the actionable part. Teams that described these prompts as "scams" can update the message to note that the same style of prompt has now been tied by CERT-UA to state-affiliated activity - which raises the perceived stakes for the exact audiences most likely to be targeted, such as staff working on Ukraine-related, government, energy, or critical-infrastructure matters. The Android angle deserves its own line in that briefing: caution against sideloading "security" apps received through messaging services is directly relevant given the disguised-APK backdoor CERT-UA describes.

For the security operations side, the implication is coverage rather than a single new indicator. Because this summarizes CERT-UA's alert as relayed through reporting, the responsible move is to confirm that existing detections for social-engineering-driven local execution are healthy, to review the CERT-UA advisory directly for any indicators an organization wishes to operationalize, and to make sure fake-CAPTCHA activity is not being auto-deprioritized on the assumption that it is only commodity crime.

Open Questions

Several details remain unsettled even with the naming in hand. It is not established whether the UAC-0145 activity is the same operation as the earlier CAPTCHA-and-PowerShell tradecraft tracked in Brief #218 or a distinct one; the sub-cluster label does not by itself answer that. A total number of infected devices is not given - CERT-UA bounds the compromised-website count but not the population of affected endpoints - so this article makes no scale claim beyond what the alert states.

It is also not confirmed whether NATO or Five-Eyes partners have issued parallel advisories tied specifically to this campaign; a CERT-UA attribution is not the same as a coordinated multi-government statement, and we are not asserting one. What is confirmed is enough to act on: CERT-UA has named UAC-0145, a GRU-affiliated Sandworm sub-cluster, behind ClickFix CAPTCHA activity against Ukrainian devices. Defenders should treat fake-CAPTCHA prompts as motivation-agnostic, keep end-user guidance focused on refusing manual fix-it instructions, and weigh follow-on primary-source detail against what is confirmed today.


The CyberSignal Analysis

The reported facts above are CERT-UA's, relayed through reporting; what follows is The CyberSignal's editorial reading of what the naming means for defenders. None of the judgments below are new reported facts, and none should be read as confirming the items we have flagged as unconfirmed.

Signal 01 - Attribution, Not a New Capability, Is the News

The temptation with a headline like this is to read it as Sandworm fielding a fearsome new technique. Our reading is the opposite: the mechanics did not reportedly change - CERT-UA supplied a name and a state affiliation for a lure family that was already in play. What moved is certainty about who is behind it, not the sophistication of the method. That is a recurring shape in this space, where effective social-engineering patterns diffuse across the actor spectrum and get formally attributed only after they have spread.

The practical consequence is that defenders should track techniques and actors on separate axes. If you assumed a fake-CAPTCHA prompt implied a criminal operator, this naming quietly invalidates that assumption for Ukraine-adjacent environments. Let corroborated attribution, not the lure itself, drive how an incident is scoped.

Signal 02 - A GRU Affiliation Reprioritizes a 'Commodity' Lure

The sub-cluster naming does real work for triage. When a technique was associated primarily with commodity crimeware, many teams implicitly scored encounters with it as opportunistic noise. Once CERT-UA ties the same pattern to a GRU-affiliated cluster, that mental shortcut becomes a liability for organizations connected to Ukraine-related, government, or critical-infrastructure work.

Our assessment is that the effective response is unchanged and mundane - reinforce the instinct to refuse manual fix-it prompts, extend that caution to sideloaded "security" apps on mobile, and keep social-engineering-driven local-execution detections healthy. The threat did not become more sophisticated; the confirmed class of actor behind a familiar lure got more serious.

Signal 03 - Hold the Line on the Unconfirmed

This story is easy to over-report, because the adjacent record is rich and it is tempting to stitch the CAPTCHA-PowerShell thread, the payload detail, and any implied partner response into one confident narrative. Our reading is that the disciplined move is to hold what is confirmed: the actor, the affiliation, the technique, and the scope CERT-UA states. Whether this overlaps Brief #218, how many devices are infected, and whether allied advisories exist are open questions, and asserting them would trade accuracy for drama.

The forward-looking interpretation is that more primary-source detail will likely follow, and when it does it should be weighed against - not merged into - the current alert. Treating this as a well-attributed naming rather than a fully mapped campaign is the posture that ages best, and it is also the one that keeps end-user guidance honest rather than alarmist.


Sources

TypeSource
PrimaryCERT-UA - alert on UAC-0145 ClickFix CAPTCHA activity
ReportingThe Hacker News - UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware
RelatedThe CyberSignal - Sandworm's CAPTCHA-and-PowerShell operation against Ukrainian targets
RelatedThe CyberSignal - Ars Technica reports Russia's Sandworm cluster now using ClickFix