
APT Lures Shift to Jobs, Code Reviews, Cloud Apps
This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…
CERT-UA reports a Sandworm-linked group (UAC-0145) is using fake CAPTCHA checks on compromised websites to persuade Ukrainian visitors to run PowerShell commands that infect their own computers. The campaign also includes Android attacks where victims are sent trojan APK “security tools” via messaging apps, resulting in a backdoor that steals files, contacts, and location.
CERT-UA has linked this campaign to UAC-0145, described as a sub-cluster within Sandworm. The core technique relies on compromised websites showing a fake CAPTCHA verification screen. Instead of clicking a checkbox, visitors are instructed to open a terminal and run a PowerShell command to "prove" they are human. That command can download and save a file, such as a VBS script, into the Windows Startup autorun directory, giving the attacker persistence on the victim's own machine. Follow-on PowerShell tooling then performs reconnaissance of the infected host.
A second track of the campaign targets Android users. Victims receive APK files through messaging apps, presented as security tools. Installing the APK delivers a full backdoor known as COWARDDUCK, which can collect contacts, targeted file types from common folders, and real-time location data, exfiltrating this information using services like the Dropbox API.
The attack succeeds because it exploits a routine, low-attention moment: passing a CAPTCHA. Most users are conditioned to click through verification prompts quickly without scrutiny. By dressing the instruction as part of that familiar flow, attackers get victims to execute the infection step themselves rather than relying on an attachment or exploit. At least 10 compromised websites were used between June and July 2026, with traffic filtering and dynamic page modification so the fake CAPTCHA is shown selectively, which helps the pages blend in and avoid broad detection. The Android lure works similarly by borrowing the credibility of the phrase "security tool."
Organizations should train staff, especially general and administrative employees plus mobile and field staff, that legitimate CAPTCHAs never require running commands. Any prompt to paste text into a terminal from a website should be treated as a likely malware delivery attempt and reported to IT. For mobile users, reinforce that software, including anything labeled a security tool, should only be installed from approved app stores or MDM channels, never from a messaging app link. Building this awareness helps staff recognize both the website-based ClickFix style lure and the Android APK lure used in this campaign.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers compromise websites to display a fake CAPTCHA verification that instructs visitors to run a PowerShell command in the terminal, which then downloads malware such as a VBS file placed in the Startup autorun directory.
It should not. A real CAPTCHA never requires running PowerShell or terminal commands, and any instruction to do so on a website is a strong sign of a social engineering attack designed to infect the visitor's own machine.
UAC-0145 also distributes Android APK files via messaging apps disguised as security tools, which actually install a backdoor called COWARDDUCK that can steal contacts, files, and real-time geolocation.
CERT-UA reports the activity targets Ukrainian users, including general staff, operations and administrative personnel, and mobile or field employees using Android devices.
Imagine this: you open a trusted site, and instead of a normal CAPTCHA, it tells you to run a PowerShell command. That’s a real tactic from UAC-0145, a Sandworm-linked group: fake CAPTCHA on a compromised site, telling Ukrainians to copy a PowerShell line that quietly drops a VBS file into Startup and runs tools like SCOUTCURL to scout the machine. Same campaign on phones: a chat message sends an APK called a 'security tool.' You install it, it’s actually the COWARDDUCK backdoor, quietly pulling contacts, documents, and real-time location, then syncing it out via Dropbox. A CAPTCHA or message that tells you to run a command or install an APK is the trap. Your move: stop, close it, and report it to security immediately, never copy commands or install tools from chat or random sites.

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

Attackers used fake Steam forum replies that looked like helpful troubleshooting steps for real gaming/PC problems. The posts tricked users into running…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft…

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…