There you have it! Russia's most elite hacking unit just adopted a trick that criminal hackers ha…
July 17, 2026 · 0 likes · 0 comments
Defense Cybersecurity
There you have it! Russia's most elite hacking unit just adopted a trick that criminal hackers have been running for a year. Not a zero-day. Not a sophisticated exploit. A fake CAPTCHA.
Full story on UnbiasedHeadlines.com: https://lnkd.in/e_SBjx6n
Ukraine's CERT-UA confirmed this week that Sandworm, a military hacking unit inside Russia's GRU, has been running fake CAPTCHA scams since the spring to break into sensitive Ukrainian networks. The technique is called Clickfix. A visitor lands on a compromised website, gets a popup telling them to "verify they're human," and the instructions say to copy a block of text and paste it into their terminal.
That text is a PowerShell script. One paste. One enter key. Malware is on the machine.
Read that again. The GRU is not burning million-dollar zero-day exploits to get inside. They are asking people to install the malware themselves.
CERT-UA identified at least 10 compromised websites rigged with these fake verification prompts. At least one confirmed network breach. The malware chain includes a recon tool called SCOUTCURL that scans installed programs, browser data, and files to decide if a machine is worth a deeper compromise. If it is, a Python-based backdoor called FreakyPoll gives Sandworm ongoing remote access.
They also built custom infrastructure called SMARTAXE that pulls targeting instructions from a smart contract so they can selectively show the fake CAPTCHA only to specific targets. Everyone else sees a normal page.
I built UnbiasedHeadlines.com to cover stories exactly like this — real cyber threats, real technical detail, zero spin. Go check it out.
The lesson here is simple. When a state-backed military intelligence unit with unlimited resources picks up a cheap social-engineering trick instead of deploying expensive exploits, it tells you one thing: the human is still the weakest link. No patch fixes that. No firewall blocks it.
You've been warned.
Full story on UnbiasedHeadlines.com: https://lnkd.in/e_SBjx6n
Ukraine's CERT-UA confirmed this week that Sandworm, a military hacking unit inside Russia's GRU, has been running fake CAPTCHA scams since the spring to break into sensitive Ukrainian networks. The technique is called Clickfix. A visitor lands on a compromised website, gets a popup telling them to "verify they're human," and the instructions say to copy a block of text and paste it into their terminal.
That text is a PowerShell script. One paste. One enter key. Malware is on the machine.
Read that again. The GRU is not burning million-dollar zero-day exploits to get inside. They are asking people to install the malware themselves.
CERT-UA identified at least 10 compromised websites rigged with these fake verification prompts. At least one confirmed network breach. The malware chain includes a recon tool called SCOUTCURL that scans installed programs, browser data, and files to decide if a machine is worth a deeper compromise. If it is, a Python-based backdoor called FreakyPoll gives Sandworm ongoing remote access.
They also built custom infrastructure called SMARTAXE that pulls targeting instructions from a smart contract so they can selectively show the fake CAPTCHA only to specific targets. Everyone else sees a normal page.
I built UnbiasedHeadlines.com to cover stories exactly like this — real cyber threats, real technical detail, zero spin. Go check it out.
The lesson here is simple. When a state-backed military intelligence unit with unlimited resources picks up a cheap social-engineering trick instead of deploying expensive exploits, it tells you one thing: the human is still the weakest link. No patch fixes that. No firewall blocks it.
You've been warned.