Fake CAPTCHAs Shift Sandworm Past Installer Detections

UAC-0145 is moving infections out of the download path and into the user prompt. A fake CAPTCHA page now gets Ukrainian targets to run a PowerShell command themselves, so the first compromise looks like normal browser activity instead of a trojanized installer. CERT-UA attributes the campaign to Sandworm and says at least 10 sites were compromised between June and July 2026. The Windows side uses the fake CAPTCHA lure to drop VBS autoruns and run SCOUTCURL, while the Android track uses fake security apps sent through messaging apps to plant the COWARDDUCK backdoor. That shift matters because controls tuned to catch malicious installers can miss a payload delivered through a copied command or a sideloaded app. The real blast radius is browser- and chat-mediated execution across Windows and Android.

Part of the PlainSec briefing for 2026-07-19

Sources