Considered one of the Russian government’s most elite hacking groups has adopted an attack, often known as Clickfix, to compromise devices belonging to sensitive organizations in Ukraine, the latter country’s CERT center is warning.
Clickfix has emerged as an efficient attack technique that attackers, primarily financially motivated criminals, began using within the last yr or so. Web sites under the control of the attackers display a CAPTCHA that requires the visitor to repeat a jumble of text and paste it into the terminal. The text incorporates scripts that, once entered, perform malicious actions, typically by installing malware or exfiltrating sensitive data. Ukraine’s CERT said Wednesday that Sandworm, a sophisticated hacking unit contained in the GRU, Russia’s military intelligence arm, is now using the technique.
“GhettoVibe,” “ScoutCurl,” and plenty of more
The Clickfix attacks began within the spring and have continued through the summer. The campaign has resulted within the network compromise of at the least one organization when a connected device was found to be infected by FreakyPoll, the name of considered one of Sandworm’s custom malware packages. Ukrainian authorities discovered 10 compromised web sites that displayed a PowerShell command as a part of a fake CAPTCHA that said it needed to be passed to make sure an actual human was behind the visiting device’s keyboard.
Once the user entered the script, it could install malicious Visual Basic scripts and other malicious wares that went on to put in a wide range of Sandworm malware. Typically, the primary malware to run was a reconnaissance program that gathered information from the infected device. Machines deemed necessary would then receive follow-on malware that backdoored the system.
“The command, for example, could possibly be intended to load and save a VBS file within the Startup directory,” a translated version of Tuesday’s advisory stated. “Considered one of the variants of such a program was called GHETTOVIBE. At the subsequent stage, in an effort to determine the importance of the cyberattack object, the SCOUTCURL software tool might be loaded onto the attacked computer, which is a PowerShell script that performs basic reconnaissance by collecting and exfiltrating information in regards to the computer: basic characteristics, programs, files, Web browser data, etc.”

