HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

UAC-0145 Deploys ClickFix CAPTCHAs to Deliver Data‑Stealing Malware to Ukrainian Targets

Russian Sandworm sub‑cluster UAC‑0145 is leveraging malicious ClickFix CAPTCHAs to infect Ukrainian users with data‑stealing malware. The campaign highlights the need for robust SOC 2 security‑awareness controls and audit‑ready evidence of training effectiveness.

LiveThreat™ Intelligence · 📅 July 19, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

UAC-0145 Deploys ClickFix CAPTCHAs to Deliver Data‑Stealing Malware to Ukrainian Targets

What Happened — Russian state‑sponsored group UAC‑0145 (a Sandworm sub‑cluster) has been observed injecting malicious ClickFix CAPTCHAs into Ukrainian web services. When users solve the CAPTCHA, a hidden payload installs data‑stealing malware on the device.

Why It Matters for Compliance & Audit Readiness

  • The attack exploits a classic social‑engineering vector that bypasses technical controls; SOC 2 access‑control criteria (CC6.1 – Security Awareness) require documented training and testing against such tactics.
  • Continuous evidence of security‑awareness program effectiveness (e.g., phishing simulations, training completion) serves as audit‑ready proof that the organization mitigates credential‑compromise risk.

Who Is Affected – Primarily Ukrainian government agencies, critical‑infrastructure operators, and any local enterprises exposed to the compromised web services.

Recommended Actions

  • Incorporate CAPTCHA‑based phishing scenarios into your security‑awareness curriculum and conduct regular simulations.
  • Verify that MFA is enforced for all privileged accounts to limit impact of credential theft.
  • Map the incident to SOC 2 CC6.1 and collect evidence of training, test results, and remediation steps for audit readiness.

Source: The Hacker News

Technical Notes – The campaign uses a “ClickFix” technique: a malicious CAPTCHA widget that, once solved, triggers a drive‑by download of a custom data‑stealer. No public CVE is associated; the vector is social engineering rather than a software flaw.

📰 Original Source
https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →