2026-07-20 · view entry permalink →
CERT-UA: Sandworm subcluster UAC-0145 pairs ClickFix fake-CAPTCHA with Ethereum-smart-contract C2 resolution and a Signal-delivered Android backdoor
CERT-UA reports that UAC-0145 — a subcluster of UAC-0002 / Sandworm (APT44, Seashell Blizzard), the GRU-linked destructive-actor family — compromised at least 10 legitimate websites between June and July 2026 to serve a fake CAPTCHA that instructs visitors to paste and run a PowerShell command in the ClickFix pattern (The Hacker News, 2026-07-19). The PowerShell one-liner drops a VBS persistence stub into the Startup folder — "one of the variants of such a program was called GHETTOVIBE," per CERT-UA — which stages a PowerShell reconnaissance script (SCOUTCURL) that profiles the host, while two loaders, FLUIDLEECH (masquerading as software for removing computer viruses) and LOADLOOP, fetch a Python backdoor, FREAKYPOLL (The Hacker News, 2026-07-19). The compromised-site injection uses a bespoke tool, SMARTAXE, layered on the commodity Cloaking.House traffic-filtering service to serve different content by visitor; the injected CAPTCHA "content to be injected into the web page employs the EtherHiding technique to retrieve the domain name of the remote resource from an Ethereum smart contract" (The Hacker News, 2026-07-19) — a eth_call-style read that replaces a hardcoded C2 domain and survives takedowns because the resolution layer lives on-chain.
Separately, UAC-0145 distributes a full-featured Android backdoor, COWARDDUCK, via Signal disguised as security software; it collects contacts, files matching targeted extensions, and real-time geolocation, uploading via the Dropbox API and pulling C2 tasking from content hosted on legitimate services (e.g. Steam Community) proxied through a public search-engine proxy — both chosen to blend into normal outbound traffic (CERT-UA, 2026-07-19). CERT-UA frames this as a continuation of its multi-year UAC-0145 tracking; the group's earlier tradecraft (trojanized torrent installers, Signal "antivirus" lures) is background — the in-window delta is the ClickFix vector, the EtherHiding C2-resolution layer, and the COWARDDUCK mobile backdoor. The ClickFix pivot marks a departure from Sandworm's prior reliance on trojanized Windows/Office installers (The Hacker News, 2026-07-19).
The CAPTCHA content to be injected into the web page employs the EtherHiding technique to retrieve the domain name of the remote resource from an Ethereum smart contract using an address specified in the source code.
The malware embedded in the APK file is a full-featured backdoor codenamed COWARDDUCK that can clandestinely collect the following details