Ukraine's Computer Emergency Response Team (CERT-UA) disclosed on July 19, 2026, that UAC-0145, a subgroup of the Russian military intelligence-linked Sandworm hacking operation, launched a cyber campaign using fake CAPTCHA prompts to trick users into executing malicious commands while concealing command-and-control infrastructure within the Ethereum blockchain. The attackers abandoned traditional malware delivery methods relying on software exploits or email attachments, instead embedding counterfeit CAPTCHA messages on compromised websites that instruct visitors to paste and execute commands via the Windows Run dialog or terminal. This tactical shift enables the operation to evade conventional endpoint security tools by leveraging legitimate system utilities and blockchain-based infrastructure that cannot be easily disabled through legal or administrative action.
CERT-UA reported that one of the campaign's most significant innovations is its use of Ethereum smart contracts to store command-and-control server addresses. Unlike conventional cyber operations that rely on registered domains or centralized hosting services, blockchain-based smart contracts cannot be easily removed, altered, or disabled through legal or administrative action.
Investigators said the attackers employed a custom tool known as SMARTAXE, which retrieves updated C2 addresses through read-only Ethereum network queries. This enables operators to redirect infected systems to new servers almost immediately while preventing defenders from disabling the underlying blockchain infrastructure. Security teams are left with the challenging task of identifying and blocking outbound requests to Ethereum Remote Procedure Call (RPC) endpoints that have been intentionally designed to resemble normal content delivery network traffic.
The advisory also noted that the attackers used Cloaking.House, a commercial traffic-filtering service that presents different website content depending on the visitor. As a result, automated security scanners often encounter harmless web pages, while intended victims receive malicious CAPTCHA prompts. CERT-UA advised that any website serving such content should be considered fully compromised, potentially through stolen administrator credentials, vulnerable content management systems, malicious plugins, or web shells.
Once a victim executes the malicious PowerShell command, a multi-stage infection sequence begins. Initial malware establishes persistence on Windows systems, followed by reconnaissance tools that collect information on hardware, installed software, browser data, and local files. Based on the collected intelligence, attackers selectively deploy additional malware families that provide persistent remote access and facilitate lateral movement within compromised networks.
The campaign also relies on legitimate administration tools, including OpenSSH and Tor, to blend malicious activity with routine network traffic. Additional modules target stored conversations from messaging applications such as Signal and WhatsApp, while stolen information is transferred using standard file synchronization utilities.
CERT-UA further identified Android malware known as COWARDDUCK, which is distributed through messaging applications disguised as security or antivirus software. Once installed, the malware collects contacts, real-time geolocation information, and files from commonly used device folders, including documents, downloads, photographs, and archives. The stolen information is transmitted through the Dropbox API, while commands are received from attacker-controlled servers and selected Steam Community pages, allowing malicious communications to blend with legitimate internet traffic.
The agency observed that the latest campaign represents a strategic shift from Sandworm's earlier reliance on trojanized software installers distributed through torrent platforms. By embedding fake CAPTCHA prompts into compromised websites, the attackers significantly expand their potential victim pool beyond individuals downloading unauthorized software.
CERT-UA urged website administrators to audit web infrastructure for unauthorized scripts, compromised plugins, and server-side backdoors while enforcing multi-factor authentication and rotating administrative credentials. The agency also recommended monitoring outbound connections for unusual traffic directed toward Ethereum RPC services and cloud storage platforms.
CERT-UA emphasized that no legitimate website, browser, or CAPTCHA service will ever instruct users to open a command prompt or system terminal and execute commands, warning that any such request should be treated as an active cyberattack and ignored immediately.
What did UAC-0145 do on July 19, 2026?
Ukraine's CERT-UA disclosed on July 19, 2026, that UAC-0145, a Sandworm subgroup, launched a cyber campaign using fake CAPTCHA prompts to trick users into executing malicious commands while concealing command-and-control infrastructure within the Ethereum blockchain.
How does Sandworm use Ethereum blockchain in cyberattacks?
Sandworm embeds command-and-control server addresses in Ethereum smart contracts, which cannot be easily removed or disabled through legal or administrative action. The attackers use a custom tool called SMARTAXE to retrieve updated C2 addresses through read-only Ethereum network queries.
What is COWARDDUCK malware?
COWARDDUCK is Android malware distributed through messaging applications disguised as security or antivirus software. Once installed, it collects contacts, real-time geolocation information, and files from device folders, transmitting stolen information through the Dropbox API while receiving commands from attacker-controlled servers and selected Steam Community pages.
Related News
FBI Warns Scammers Use AI to Impersonate Agents in Recovery Fraud
OpenAI discloses GPT-5.6’s breakthrough in the Sol sandbox, hacking into Hugging Face to steal benchmark answers
Human.tech Launches Clean SDK for Private Web3 Compliance on Aztec
FBI Reports $11.4B Crypto Fraud Losses in 2025 as Kiosk Scams Surge