In 2026, two Russian-linked cyberattacks against Ukrainian targets – both build around a deceptively simple fake CAPTCHA scam – where GRU-linked hackers expanded attacks against their systems through on compromised websites.
The deceptively simple trick convinced users to paste malicious PowerShell commands into Windows and turning victims into the attackers’ entry point.
The technique exposed a deeper weakness in cybersecurity, especially when an employee is persuaded to personally execute the command that opens a system. Even strong security tools face a difficult problem with distinguishing normal user activity from actions carefully manipulated by an attacker.
When hackers get in by getting a user to type a command, is the resulting damage really a failure of sophisticated tradecraft, or a basic security hygiene?
Experts Warn About a New Scam Using Fake Captcha Screen
Ukraine’s computer emergency response team, CERT-UA, claimed the Sandworm-linked UAC-0145 group relied on a CAPTCHA scam during June and July 2026, placing deceptive verification screens across more than 10 compromised websites used to reach Ukrainian targets.
Unlike a real CAPTCHA, the page did not simply ask visitors to select images or confirm they were human. Instead, fake CAPTCHA scam instructed them to copy a PowerShell command, open a Windows tool and paste the command themselves, allowing malicious code to begin running.
The Russian CAPTCHA attack is part of a social engineering method known as ClickFix. Instead of exploiting a hidden software weakness first, ClickFix convinces a person to carry out technical steps that would normally appear suspicious if performed automatically.
CERT-UA said the initial malware, called GhettoVibe, can establish access before attackers deploy ScoutCurl. The reconnaissance tool gathers system information, installed software, files and browser data, helping operators understand what is available on the infected computer before deciding whether to continue the intrusion.
The CAPTCHA Russian campaign has also involved malware loaders known as FluidLeech and LoadLoop. FluidLeech appears to victims as antivirus-removal software, giving malicious activity the appearance of a legitimate security process while helping attackers introduce additional tools.
That deception matters because the fake CAPTCHA scam does not necessarily look like a conventional cyberattack. A victim might believe they are completing an ordinary website security step, particularly as CAPTCHA checks have become a familiar part of everyday browsing.
CERT-UA also warned that Sandworm continues targeting mobile devices. A form of fake hacker alerts can appear through security-themed Android applications distributed over messaging platforms. Once installed, the malware can collect contacts, files, device information, and even real-time location data.
Sandworm has previously used backdoored versions of Microsoft Windows and Office installers distributed through torrent websites. CERT-UA said one such infection eventually gave attackers access to a Ukrainian government network before a destructive operation was carried out against a central executive authority.
The threat shows how CAPTCHA hacking increasingly mixes technical malware with psychological manipulation. Instead of searching solely for unpatched software, attackers create instructions that make users believe dangerous commands are necessary to access a page or prove they are human.
User Plans His Attack
In April, cybersecurity researchers at Cisco discovered unusual activity inside a Ukrainian government organization’s computer system, later attributing the intrusion “with moderate confidence” to a Russian threat actor.
Researchers identified Amatera information-stealing malware inside the Ukrainian organization after detecting a suspicious file named “verification.google,” although they could not confirm how the initial infection happened.
According to Cisco, malware steal sensitive information and install additional software capable of giving attackers access to files and commands. Researchers also found infrastructure connected to a Russian IP address and attributed the operation with moderate confidence to a Russian threat actor.
“It was not clear what started the execution chain,” said Cisco researchers.
To understand the possible entry method, researchers examined another Amatera infection and discovered an example of fake CAPTCHA prompt designed to imitate Google verification. Users were instructed to open a Windows interface and paste text that actually executed malware.
Moreover, the attack installed cryptocurrency-stealing software. It holds a scary ability to watch cryptocurrency wallet addresses copied by victims and replace them with attacker-controlled addresses, potentially redirecting transfers.
Cisco assessed that the broader activity likely aimed to steal cryptocurrency and login credentials.
The similarities raise the possibility that the Ukrainian infection was connected to the same Russian CAPTCHA technique, although Cisco stressed that it could not confirm the two attacks began identically or were conducted by the same operators.
For organizations, simply teaching employees to block CAPTCHA prompt messages may not be enough. Modern attacks increasingly reproduce familiar interfaces closely enough that users may not immediately recognize when a normal verification process has turned into a request to execute code.
The second CAPTCHA scam lesson is therefore less about whether employees understand malware and more about whether they recognize unusual behavior. A legitimate CAPTCHA should not require users to open PowerShell, paste commands or manually execute instructions on their operating system.
Similarly, fake hacker alerts and fake security applications work because they create urgency and authority. An employee who believes a device is at risk may follow instructions more quickly, giving attackers exactly the access that security protections were designed to prevent.
If a device becomes CAPTCHA hacked because its legitimate user willingly executes the first malicious command, traditional security boundaries become harder to defend. The attacker has effectively transformed social engineering into an execution mechanism.
That is what makes the CAPTCHA Russian approach relevant beyond one Ukrainian campaign. Nation-state attackers do not always need their most sophisticated technical capabilities if ordinary browser habits can be manipulated into producing the same initial access.
The concern behind the fake CAPTCHA scam is not whether Sandworm can build advanced malware, but whether infrastructure can withstand attacks that begin with something far simpler associated with convincing a trusted employee to perform the attacker’s first command.
Inside Telecom provides you with an extensive list of content covering all aspects of the tech industry. Keep an eye on our Intelligent Tech sections to stay informed and up-to-date with our daily articles.
