<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/now-even-russia-s-most-elite-hackers-are-using-clickfix-to-infect-devices-ifkhhbbii" -->

---
title: Now, even Russia’s most elite hackers are using Clickfix...
description: Ukraine&#x27;s CERT has warned that Sandworm, an elite GRU-linked Russian hacking group, is now using the Clickfix social-engineering technique to compromise...
canonical: https://daily.dev/posts/now-even-russia-s-most-elite-hackers-are-using-clickfix-to-infect-devices-ifkhhbbii
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Now, even Russia’s most elite hackers are using Clickfix to infect devices | daily.dev
og:description: Ukraine&#x27;s CERT has warned that Sandworm, an elite GRU-linked Russian hacking group, is now using the Clickfix social-engineering technique to compromise...
og:url: https://daily.dev/posts/now-even-russia-s-most-elite-hackers-are-using-clickfix-to-infect-devices-ifkhhbbii
og:image: https://api.daily.dev/og/posts/ifkHHBBiI.png
og:image:alt: Now, even Russia’s most elite hackers are using Clickfix to infect devices
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Now, even Russia’s most elite hackers are using Clickfix to infect devices

**[Ars Technica](https://daily.dev/sources/arstechnica)** · 2 min read · 3 upvotes · 0 comments

## Summary

Ukraine's CERT has warned that Sandworm, an elite GRU-linked Russian hacking group, is now using the Clickfix social-engineering technique to compromise Ukrainian organizations. Clickfix tricks users into copying and pasting a PowerShell command disguised as a CAPTCHA verification, which then installs malicious VBS scripts and custom Sandworm malware packages such as GHETTOVIBE and SCOUTCURL. The campaign began in spring and has led to at least one confirmed network compromise. SCOUTCURL performs reconnaissance by collecting system info, browser data, and files, while GHETTOVIBE establishes persistence via the Startup directory. Previously associated mainly with financially motivated criminals, Clickfix is now being adopted by nation-state threat actors.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://arstechnica.com/security/2026/07/now-even-russias-most-elite-hackers-are-using-clickfix-to-infect-devices>

## Questions this post answers

### What is the Clickfix attack technique and how does it infect a computer?

Clickfix is a social-engineering attack where a malicious website displays a fake CAPTCHA instructing the visitor to copy a block of text and paste it into their terminal or Run dialog. That pasted text is actually a script, often PowerShell or Visual Basic, that executes malicious actions such as installing malware or exfiltrating data once run by the victim.

_Track emerging social-engineering attack techniques like clickfix on daily.dev to spot the pattern before you click._

### Which Russian hacking group is now using Clickfix and what malware have they deployed with it?

Sandworm, an advanced hacking unit within Russia's GRU military intelligence, has been using Clickfix since spring against Ukrainian organizations. Discovered tools include GHETTOVIBE, a Visual Basic script that installs persistence via the Startup directory, SCOUTCURL, a PowerShell reconnaissance tool that exfiltrates system and browser data, and FreakyPoll, custom malware found on at least one compromised network.

_Security teams monitoring nation-state threat actors like Sandworm can follow updates on daily.dev._

## Similar posts on daily.dev

- [ClickFix techniques evolve in new infostealer campaigns](https://daily.dev/posts/clickfix-techniques-evolve-in-new-infostealer-campaigns-mufrpsfhw) · CSO Online · 0 upvotes · 0 comments
- [ClickFix may be the biggest security threat your family has never heard of](https://daily.dev/posts/clickfix-may-be-the-biggest-security-threat-your-family-has-never-heard-of-p29pgiik1) · Ars Technica · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#malware](https://daily.dev/tags/malware), [#powershell](https://daily.dev/tags/powershell)

[View this post on daily.dev](https://daily.dev/posts/now-even-russia-s-most-elite-hackers-are-using-clickfix-to-infect-devices-ifkhhbbii)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Now, even Russia’s most elite hackers are using Clickfix to infect devices","url":"https://daily.dev/posts/now-even-russia-s-most-elite-hackers-are-using-clickfix-to-infect-devices-ifkhhbbii","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/now-even-russia-s-most-elite-hackers-are-using-clickfix-to-infect-devices-ifkhhbbii"},"datePublished":"2026-07-16T20:26:47.184Z","dateModified":"2026-09-14T07:38:10.252Z","description":"Ukraine's CERT has warned that Sandworm, an elite GRU-linked Russian hacking group, is now using the Clickfix social-engineering technique to compromise...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/cc2c90cb2cc43831eef1e57256970b6e?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/cc2c90cb2cc43831eef1e57256970b6e?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Ars Technica","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Ars Technica","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/80883e0e48a34b5ebcf93777016cb3fe","url":"https://daily.dev/sources/arstechnica"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/now-even-russia-s-most-elite-hackers-are-using-clickfix-to-infect-devices-ifkhhbbii","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":3},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,malware,powershell","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Ars Technica","item":"https://daily.dev/sources/arstechnica"},{"@type":"ListItem","position":3,"name":"Now, even Russia’s most elite hackers are using Clickfix to infect devices"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/now-even-russia-s-most-elite-hackers-are-using-clickfix-to-infect-devices-ifkhhbbii#faq","mainEntity":[{"@type":"Question","name":"What is the Clickfix attack technique and how does it infect a computer?","acceptedAnswer":{"@type":"Answer","text":"Clickfix is a social-engineering attack where a malicious website displays a fake CAPTCHA instructing the visitor to copy a block of text and paste it into their terminal or Run dialog. That pasted text is actually a script, often PowerShell or Visual Basic, that executes malicious actions such as installing malware or exfiltrating data once run by the victim. Track emerging social-engineering attack techniques like clickfix on daily.dev to spot the pattern before you click."}},{"@type":"Question","name":"Which Russian hacking group is now using Clickfix and what malware have they deployed with it?","acceptedAnswer":{"@type":"Answer","text":"Sandworm, an advanced hacking unit within Russia's GRU military intelligence, has been using Clickfix since spring against Ukrainian organizations. Discovered tools include GHETTOVIBE, a Visual Basic script that installs persistence via the Startup directory, SCOUTCURL, a PowerShell reconnaissance tool that exfiltrates system and browser data, and FreakyPoll, custom malware found on at least one compromised network. Security teams monitoring nation-state threat actors like Sandworm can follow updates on daily.dev."}}]}
```

