Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Ukraine Warns of Sandworm’s Blockchain-Based Cyberattack Tactics

Ukraine Warns of Sandworm’s Blockchain-Based Cyberattack Tactics

CERT-UA Says GRU-Linked Hackers Use Fake CAPTCHA Prompts and Ethereum

Kelly Cromley by Kelly Cromley
Jul 22, 2026
in Market News, News
Reading Time: 3 mins read
0
Ukraine

Ukraine’s Computer Emergency Response Team (CERT-UA) has disclosed a sophisticated cyber campaign attributed to UAC-0145, a subgroup of the Russian military intelligence-linked Sandworm hacking operation. In an advisory issued on July 19, 2026, the agency reported that the attackers had significantly changed their tactics by relying on fake CAPTCHA prompts to trick users into infecting their own computers while concealing command-and-control (C2) infrastructure within the Ethereum blockchain.

According to CERT-UA, the campaign abandons traditional malware delivery methods that depend on software exploits or malicious email attachments. Instead, compromised websites display counterfeit CAPTCHA or error messages instructing visitors to open the Windows Run dialog or terminal, paste a command that has already been copied to the clipboard by embedded JavaScript, and execute it. Because victims unknowingly launch the malicious command themselves using legitimate system utilities, the attack can evade conventional endpoint security tools that typically monitor suspicious software installations.

CERT-UA reported that Sandworm has adopted fake CAPTCHA prompts and Ethereum-based command infrastructure, marking a significant evolution in the group’s cyberattack techniques and making disruption considerably more difficult.

Blockchain Infrastructure Complicates Defensive Measures

Investigators said one of the campaign’s most significant innovations is its use of Ethereum smart contracts to store C2 server addresses. Unlike conventional cyber operations that rely on registered domains or centralized hosting services, blockchain-based smart contracts cannot be easily removed, altered, or disabled through legal or administrative action.

CERT-UA explained that the attackers employed a custom tool known as SMARTAXE, which retrieves updated C2 addresses through read-only Ethereum network queries. This enables operators to redirect infected systems to new servers almost immediately while preventing defenders from disabling the underlying blockchain infrastructure. Security teams are therefore left with the challenging task of identifying and blocking outbound requests to Ethereum Remote Procedure Call (RPC) endpoints that have been intentionally designed to resemble normal content delivery network traffic.

The advisory also noted that the attackers used Cloaking.House, a commercial traffic-filtering service that presents different website content depending on the visitor. As a result, automated security scanners often encounter harmless web pages, while intended victims receive malicious CAPTCHA prompts. CERT-UA advised that any website serving such content should be considered fully compromised, potentially through stolen administrator credentials, vulnerable content management systems, malicious plugins, or web shells.

Multi-Platform Malware Targets Windows and Android

Once a victim executes the malicious PowerShell command, a multi-stage infection sequence begins. Initial malware establishes persistence on Windows systems, followed by reconnaissance tools that collect information on hardware, installed software, browser data, and local files. Based on the collected intelligence, attackers selectively deploy additional malware families that provide persistent remote access and facilitate lateral movement within compromised networks.

The campaign also relies on legitimate administration tools, including OpenSSH and Tor, to blend malicious activity with routine network traffic. Additional modules target stored conversations from messaging applications such as Signal and WhatsApp, while stolen information is transferred using standard file synchronization utilities.

The operation deploys a layered malware framework targeting both Windows and Android devices, combining reconnaissance, persistent remote access, credential theft, messaging data collection, and cloud-based data exfiltration.

CERT-UA further identified Android malware known as COWARDDUCK, which is distributed through messaging applications disguised as security or antivirus software. Once installed, the malware collects contacts, real-time geolocation information, and files from commonly used device folders, including documents, downloads, photographs, and archives. The stolen information is transmitted through the Dropbox API, while commands are received from attacker-controlled servers and selected Steam Community pages, allowing malicious communications to blend with legitimate internet traffic.

The agency observed that the latest campaign represents a strategic shift from Sandworm’s earlier reliance on trojanized software installers distributed through torrent platforms. By embedding fake CAPTCHA prompts into compromised websites, the attackers significantly expand their potential victim pool beyond individuals downloading unauthorized software.

CERT-UA Urges Stronger Web Security Measures

CERT-UA urged website administrators to audit web infrastructure for unauthorized scripts, compromised plugins, and server-side backdoors while enforcing multi-factor authentication and rotating administrative credentials. The agency also recommended monitoring outbound connections for unusual traffic directed toward Ethereum RPC services and cloud storage platforms.

CERT-UA emphasized that no legitimate website, browser, or CAPTCHA service will ever instruct users to open a command prompt or system terminal and execute commands, warning that any such request should be treated as an active cyberattack and ignored immediately.

Previous Post

NodeMeta Expands Web3 Vision With AI, Security, and NTE Ecosystem

Related Posts

node meta

NodeMeta Expands Web3 Vision With AI, Security, and NTE Ecosystem

by Kelly Cromley
Jul 22, 2026
0

NodeMeta is advancing the development of a community-driven Web3 ecosystem centered on its NTE utility token, with a long-term strategy...

OKX

OKX Launches Social Login to Simplify Web3 Wallet Access

by Kelly Cromley
Jul 22, 2026
0

OKX has introduced a major upgrade to its self-custody wallet by launching a Social Login feature designed to simplify the...

valereum

Valereum Expands Digital Asset Strategy Across Africa

by Kelly Cromley
Jul 22, 2026
0

Valereum PLC has entered into a strategic partnership with Blockchain Digital Assets Limited (Africa) (BDAL), also known as Koinon, as...

Blockchain.com

Blockchain.com Backs OpenWorld to Accelerate RWA Tokenization

by Kelly Cromley
Jul 21, 2026
0

OpenWorld Ltd., a blockchain infrastructure company focused on real-world asset (RWA) tokenization, has entered into a multi-year strategic partnership with...

ripple

Ripple Prime Expands XRP’s Institutional Role in 24/7 Finance

by Kelly Cromley
Jul 21, 2026
0

Ripple Prime is accelerating its push into institutional finance by positioning itself as a key infrastructure provider for blockchain-powered capital...

human tech

Human.tech Launches Clean SDK for Private, Compliant Web3 Apps

by Kelly Cromley
Jul 21, 2026
0

Human.tech has introduced the Clean SDK, a developer toolkit designed to integrate privacy-preserving identity verification and sanctions screening into Web3...

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

Ukraine
Market News

Ukraine Warns of Sandworm’s Blockchain-Based Cyberattack Tactics

by Kelly Cromley
Jul 22, 2026
node meta
Market News

NodeMeta Expands Web3 Vision With AI, Security, and NTE Ecosystem

by Kelly Cromley
Jul 22, 2026
OKX
Market News

OKX Launches Social Login to Simplify Web3 Wallet Access

by Kelly Cromley
Jul 22, 2026
valereum
Market News

Valereum Expands Digital Asset Strategy Across Africa

by Kelly Cromley
Jul 22, 2026
Blockchain.com
Market News

Blockchain.com Backs OpenWorld to Accelerate RWA Tokenization

by Kelly Cromley
Jul 21, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.