DigiNews

Tech Watch by Johan Denoyer

← Back to articles

Now, even Russia's most elite hackers are using Clickfix to infect devices

Quality: 9/10 Relevance: 9/10

Summary

Ars Technica reports that Russia’s elite hacking group Sandworm has adopted the Clickfix social-engineering technique to compromise devices belonging to sensitive Ukrainian organizations. The attack uses fake CAPTCHA challenges that prompt users to run PowerShell scripts, dropping malware such as FreakyPoll, GHETTOVIBE, and SCOUTCURL for reconnaissance and data exfiltration. The advisory details multiple attack chains and urges defenders to monitor for compromised web resources and backdoors, highlighting a broader shift in attacker tradecraft.

🚀 Service construit par Johan Denoyer