<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/now-even-russia-s-most-elite-hackers-are-using-clickfix-to-infect-devices-ifkhhbbii" -->

---
title: Now, even Russia’s most elite hackers are using Clickfix...
description: Ukraine&#x27;s CERT has warned that Sandworm, an elite GRU-linked Russian hacking group, is now using the Clickfix social-engineering technique to compromise...
canonical: https://daily.dev/posts/now-even-russia-s-most-elite-hackers-are-using-clickfix-to-infect-devices-ifkhhbbii
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Now, even Russia’s most elite hackers are using Clickfix to infect devices | daily.dev
og:description: Ukraine&#x27;s CERT has warned that Sandworm, an elite GRU-linked Russian hacking group, is now using the Clickfix social-engineering technique to compromise...
og:url: https://daily.dev/posts/now-even-russia-s-most-elite-hackers-are-using-clickfix-to-infect-devices-ifkhhbbii
og:image: https://api.daily.dev/og/posts/ifkHHBBiI.png
og:image:alt: Now, even Russia’s most elite hackers are using Clickfix to infect devices
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Now, even Russia’s most elite hackers are using Clickfix to infect devices

**[Ars Technica](https://daily.dev/sources/arstechnica)** · 2 min read · 3 upvotes · 0 comments

## Summary

Ukraine's CERT has warned that Sandworm, an elite GRU-linked Russian hacking group, is now using the Clickfix social-engineering technique to compromise Ukrainian organizations. Clickfix tricks users into copying and pasting a PowerShell command disguised as a CAPTCHA verification, which then installs malicious VBS scripts and custom Sandworm malware packages such as GHETTOVIBE and SCOUTCURL. The campaign began in spring and has led to at least one confirmed network compromise. SCOUTCURL performs reconnaissance by collecting system info, browser data, and files, while GHETTOVIBE establishes persistence via the Startup directory. Previously associated mainly with financially motivated criminals, Clickfix is now being adopted by nation-state threat actors.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://arstechnica.com/security/2026/07/now-even-russias-most-elite-hackers-are-using-clickfix-to-infect-devices>

## Similar posts on daily.dev

- [ClickFix techniques evolve in new infostealer campaigns](https://daily.dev/posts/clickfix-techniques-evolve-in-new-infostealer-campaigns-mufrpsfhw) · CSO Online · 0 upvotes · 0 comments
- [ClickFix may be the biggest security threat your family has never heard of](https://daily.dev/posts/clickfix-may-be-the-biggest-security-threat-your-family-has-never-heard-of-p29pgiik1) · Ars Technica · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#malware](https://daily.dev/tags/malware), [#powershell](https://daily.dev/tags/powershell)

[View this post on daily.dev](https://daily.dev/posts/now-even-russia-s-most-elite-hackers-are-using-clickfix-to-infect-devices-ifkhhbbii)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Now, even Russia’s most elite hackers are using Clickfix to infect devices","url":"https://daily.dev/posts/now-even-russia-s-most-elite-hackers-are-using-clickfix-to-infect-devices-ifkhhbbii","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/now-even-russia-s-most-elite-hackers-are-using-clickfix-to-infect-devices-ifkhhbbii"},"datePublished":"2026-07-16T20:26:47.184Z","dateModified":"2026-07-16T20:27:09.633Z","description":"Ukraine's CERT has warned that Sandworm, an elite GRU-linked Russian hacking group, is now using the Clickfix social-engineering technique to compromise...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/cc2c90cb2cc43831eef1e57256970b6e?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/cc2c90cb2cc43831eef1e57256970b6e?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Ars Technica","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Ars Technica","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/80883e0e48a34b5ebcf93777016cb3fe","url":"https://daily.dev/sources/arstechnica"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/now-even-russia-s-most-elite-hackers-are-using-clickfix-to-infect-devices-ifkhhbbii","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":3},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,malware,powershell","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Ars Technica","item":"https://daily.dev/sources/arstechnica"},{"@type":"ListItem","position":3,"name":"Now, even Russia’s most elite hackers are using Clickfix to infect devices"}]}
```

