A recent warning issued by Ukraine’s Computer Emergency Response Team (CERT-UA) has highlighted the emergence of new tactics employed by the Russia-linked hacking group UAC-0145. The group, which has been associated with previous attacks on Ukrainian government and military entities, has now shifted its focus towards spreading malware through cunningly disguised CAPTCHA prompts on compromised websites.
According to CERT-UA, the latest campaigns involve hacked websites displaying fake CAPTCHA challenges that prompt users to run malicious commands, leading to potential malware infections. This deceptively simple tactic leverages the users’ trust in the website’s authenticity, allowing the hackers to gain access to sensitive information and install malicious software on targeted devices.
In addition to these website-based attacks, UAC-0145 has also been spreading malware through other methods, including the distribution of fake antivirus software via the encrypted messaging app Signal. This software, masquerading as a legitimate security tool, is designed to deceive unsuspecting users into installing malicious code on their devices.
Furthermore, the group has been observed deploying a fake Android security app that steals sensitive user data, including contacts, files, and real-time location information. This Android app, designed to appear as a legitimate security solution, appears to be an especially insidious tactic, given the widespread use of mobile devices among the general public.
CERT-UA has revealed that victims of these campaigns include Ukrainian government and military-linked users, emphasizing the necessity for swift action to counter these threats. To mitigate the risk of infection, the team has urged website administrators and hosting providers to conduct thorough checks for compromise and report any suspicious activity to the relevant authorities.
In a statement, CERT-UA emphasized the importance of vigilance in the face of these evolving cyber threats. “We urge all Ukrainian citizens to exercise caution when interacting with online resources, particularly those related to the military and government sectors,” the team said. “It is essential to remain aware of potential security risks and to report any suspicious activity to the relevant authorities.”
As UAC-0145 continues to exploit new vulnerabilities, the international community is reminded of the critical need for cybersecurity awareness and cooperation to counter these complex threats. By working together to share intelligence and best practices, nations and organizations can better safeguard against the escalating threat of cyberattacks and protect the digital futures of all citizens.
