Technology British Columbia

Now, even Russia's most elite hackers are using Clickfix to infect devices

The social-engineering technique has primarily been a tool of financially motivated criminals.

Now, even Russia's most elite hackers are using Clickfix to infect devices
Text to audio Audio version available

The social-engineering technique has primarily been a tool of financially motivated criminals.

One of the Russian government’s most elite hacking groups has adopted an attack, known as Clickfix, to compromise devices belonging to sensitive organizations in Ukraine, the latter country’s CERT center is warning. Clickfix has emerged as an effective attack technique that attackers, primarily financially motivated criminals, began using in the last year or so. Websites under the control of the attackers display a CAPTCHA that requires the visitor to copy a jumble of text and paste it into the terminal.

The text contains scripts that, once entered, perform malicious actions, typically by installing malware or exfiltrating sensitive data. Ukraine’s CERT said Wednesday that Sandworm, an advanced hacking unit inside the GRU, Russia’s military intelligence arm, is now using the technique. “GhettoVibe,” “ScoutCurl,” and many more The Clickfix attacks began in the spring and have continued through the summer.

The campaign has resulted in the network compromise of at least one organization when a connected device was found to be infected by FreakyPoll, the name of one of Sandworm’s custom malware packages. Ukrainian authorities discovered 10 compromised websites that displayed a PowerShell command as part of a fake CAPTCHA that said it had to be passed to ensure a real human was behind the visiting device’s keyboard. Once the user entered the script, it could install malicious Visual Basic scripts and other malicious wares that went on to install a variety of Sandworm malware.

Typically, the first malware to run was a reconnaissance program that gathered information from the infected device. Machines deemed important would then receive follow-on malware that backdoored the system. “The command, as an example, could be intended to load and save a VBS file in the Startup directory,” a translated version of Tuesday’s advisory stated.

“One of the variants of such a program was called GHETTOVIBE. At the next stage, in order to determine the importance of the cyberattack object, the SCOUTCURL software tool can be loaded onto the attacked computer, which is a PowerShell script that performs basic reconnaissance by collecting and exfiltrating information about the computer: basic characteristics, programs, files, Internet browser data, etc.”

Published
Jul 16, 2026
Updated
Jul 16, 2026
Source
Ars Technica
Category
Technology
Read time
2 min
Key facts

Key facts

SectionTechnology
Open
SourceArs Technica
Open
PublishedJul 16, 2026
UpdatedJul 16, 2026

Why this matters locally

This technology story matters locally because it may affect readers, businesses, commuters, families, or public services in British Columbia.

Local impact

BC Post links this item to British Columbia coverage so readers can follow related city updates, weather, traffic, events, and category news in one place.

Timeline

PublishedJul 16, 2026, 12:28 PMThis story was published by BC Post.
ImportedJul 16, 2026, 2:01 PMThe item entered the BC Post source pipeline.
Transparency

Source and credit

BC Post may summarize, organize, and add local context for reader clarity. Original reporting remains with the listed publisher.

Ars Technica Published Jul 16, 2026 Imported Jul 16, 2026
Read Original Source
Ars Technica Jul 16, 2026
Read Original Source