Ukraine's CERT-UA Discloses Sandworm's Fake CAPTCHA and Ethereum-Based C2 Attack Tactics on July 19

ETH0.13%

According to Ukraine's Computer Emergency Response Team (CERT-UA), on July 19, 2026, the agency disclosed a sophisticated cyberattack campaign attributed to UAC-0145, a subgroup of Russian military intelligence-linked Sandworm, that employs fake CAPTCHA prompts and Ethereum-based command infrastructure. The attackers trick users into executing malicious commands through counterfeit CAPTCHA messages on compromised websites, while using Ethereum smart contracts to store command-and-control server addresses—a technique that cannot be easily disrupted through conventional legal or administrative action.

CERT-UA identified the custom tool SMARTAXE, which retrieves updated C2 addresses via Ethereum network queries, enabling attackers to redirect infected systems almost immediately. The campaign also deploys multi-platform malware targeting Windows and Android devices, including COWARDDUCK, which collects contacts, geolocation, and files from messaging applications through the Dropbox API. CERT-UA warned that no legitimate website or CAPTCHA service will ever instruct users to execute system commands, and urged website administrators to audit infrastructure for unauthorized scripts and enforce multi-factor authentication.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments