Actor Profile
UAC-0145 is a sub-cluster of Sandworm, a Russian state-sponsored APT group attributed to the GRU (Main Intelligence Directorate of the General Staff of the Armed Forces of the Russian Federation). Sandworm is known for highly disruptive cyber operations, including destructive attacks and espionage campaigns. UAC-0145 operates as part of this broader GRU-affiliated threat ecosystem, conducting targeted intrusion operations aligned with Russian strategic interests. The actor's motivation is intelligence collection and potential disruption of Ukrainian entities in support of ongoing geopolitical conflict.
TTPs (Tactics, Techniques, Procedures)
UAC-0145 employs social engineering tactics leveraging fake CAPTCHA prompts (ClickFix technique) to deceive victims into executing malicious code. This technique abuses user trust in legitimate web security mechanisms to achieve initial access (T1204.001 - User Execution: Malicious Link, T1204.002 - User Execution: Malicious File). The campaign delivers data-stealing malware, indicating follow-on objectives of credential access (T1555 - Credentials from Password Stores, T1539 - Steal Web Session Cookie) and collection (T1005 - Data from Local System, T1113 - Screen Capture). The use of ClickFix CAPTCHA lures represents an evolution in social engineering tradecraft, exploiting user familiarity with CAPTCHA challenges to lower suspicion during initial compromise.
Targets & Patterns
The campaign specifically targets Ukrainian entities, consistent with UAC-0145 and Sandworm's historical focus on Ukraine as a primary intelligence and disruption target. While specific sectors are not identified in this campaign, Sandworm has historically targeted critical infrastructure, government, military, and energy sectors in Ukraine. The targeting pattern aligns with Russian strategic intelligence priorities related to the ongoing conflict, aiming to collect sensitive information from Ukrainian individuals and organizations. The use of social engineering suggests the actor is casting a relatively broad net within the Ukrainian threat landscape, relying on user interaction rather than technical exploitation for initial access.
Historical Context
Sandworm is one of the most prolific and destructive Russian APT groups, responsible for major campaigns including NotPetya (2017), BlackEnergy attacks against Ukrainian power infrastructure (2015-2016), and Olympic Destroyer (2018). UAC-0145, as a sub-cluster, represents operational compartmentalization within the broader Sandworm apparatus. The use of ClickFix social engineering tactics marks a tactical evolution from Sandworm's historically infrastructure-focused destructive operations, though data theft remains a consistent objective. CERT-UA, Ukraine's national CERT, has tracked UAC-0145 as part of ongoing monitoring of Russian threat activity targeting Ukrainian cyberspace. This campaign continues Sandworm's sustained targeting of Ukraine throughout the current geopolitical conflict.
Defensive Recommendations
- Implement user awareness training specifically addressing fake CAPTCHA and ClickFix social engineering tactics, emphasizing that legitimate CAPTCHAs never require users to execute code or run commands
- Deploy endpoint detection and response (EDR) solutions configured to detect and block execution of scripts initiated from browser contexts, particularly PowerShell (T1059.001) or command-line interpreters launched by user interaction
- Enable application whitelisting and restrict execution of scripts from user-writable directories (e.g., Downloads, Temp) to prevent execution of malware delivered via social engineering
- Monitor for unusual credential access patterns and data exfiltration behaviors consistent with information-stealing malware, including access to browser credential stores (T1555.003) and web session cookies (T1539)
- Leverage threat intelligence from CERT-UA and other Ukrainian cybersecurity entities to proactively block known UAC-0145 and Sandworm infrastructure, domains, and ClickFix-related indicators of compromise
---
# Geopolitical Context
Geopolitical Context
The campaign attributed to UAC-0145, assessed to be a sub-cluster of Sandworm, reflects the ongoing cyber dimension of Russia's conflict with Ukraine. Sandworm, linked to Russia's Main Intelligence Directorate (GRU Unit 74455), has historically conducted disruptive and espionage operations against Ukrainian critical infrastructure and government entities since at least 2015. The adoption of ClickFix social engineering—a technique that exploits fake CAPTCHA prompts to deliver malware—indicates continued tactical evolution by GRU-affiliated actors. This activity is consistent with sustained intelligence collection efforts against Ukrainian individuals and organizations amid the protracted military conflict. The use of data-stealing malware suggests objectives centered on credential harvesting, reconnaissance, and potential pre-positioning for follow-on operations.
State Actor Alignment
UAC-0145 is assessed by CERT-UA to operate as a sub-cluster within the Sandworm threat group, which Western governments and cybersecurity organizations have attributed to Russia's GRU military intelligence service. Sandworm has been subject to indictments by the U.S. Department of Justice and sanctions designations by the U.S., EU, and UK for its role in destructive cyberattacks, including NotPetya (2017) and attacks on Ukrainian power infrastructure. The current campaign aligns with Russia's strategic use of cyber operations as an instrument of statecraft in its ongoing conflict with Ukraine, blending espionage with potential disruptive capabilities.
Business Impacty pro region
This activity underscores the persistent cyber threat environment facing Ukraine, where state-sponsored intrusions remain a daily reality for government, military, and civilian networks. For European allies and NATO members, the campaign serves as a reminder of the GRU's operational tempo and adaptability, particularly in refining social engineering tradecraft. The use of ClickFix tactics—previously observed in cybercriminal and espionage contexts—may signal diffusion of techniques across threat actor ecosystems. European cybersecurity agencies should anticipate potential spillover or targeting of Ukrainian diaspora communities, NGOs, and partner organizations operating in support of Ukraine. The incident reinforces the importance of information sharing through platforms such as the EU Cyber Rapid Response Teams and continued defensive support to Kyiv.
Forecast
If UAC-0145 and related GRU sub-clusters continue to refine social engineering methods such as ClickFix, Ukrainian and allied networks may face increased risk of credential compromise and lateral movement by sophisticated state actors. Should the campaign expand beyond Ukraine, targeting of European government, defense, or logistics entities supporting Ukrainian operations is plausible. Continued vigilance and user awareness training will be critical to mitigating the effectiveness of these lures. If geopolitical tensions escalate or coincide with military developments, an uptick in both espionage and disruptive cyber activity by Sandworm-affiliated actors is likely.
