Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » Ukraine Warns of Sandworm’s Blockchain-Based Cyberattack Tactics

Ukraine Warns of Sandworm’s Blockchain-Based Cyberattack Tactics

CERT-UA Says GRU-Linked Hackers Use Fake CAPTCHA Prompts and Ethereum

Kelly Cromley by Kelly Cromley
Jul 22, 2026
in Market News, News
Reading Time: 3 mins read
0
Ukraine

Ukraine’s Computer Emergency Response Team (CERT-UA) has disclosed a sophisticated cyber campaign attributed to UAC-0145, a subgroup of the Russian military intelligence-linked Sandworm hacking operation. In an advisory issued on July 19, 2026, the agency reported that the attackers had significantly changed their tactics by relying on fake CAPTCHA prompts to trick users into infecting their own computers while concealing command-and-control (C2) infrastructure within the Ethereum blockchain.

According to CERT-UA, the campaign abandons traditional malware delivery methods that depend on software exploits or malicious email attachments. Instead, compromised websites display counterfeit CAPTCHA or error messages instructing visitors to open the Windows Run dialog or terminal, paste a command that has already been copied to the clipboard by embedded JavaScript, and execute it. Because victims unknowingly launch the malicious command themselves using legitimate system utilities, the attack can evade conventional endpoint security tools that typically monitor suspicious software installations.

CERT-UA reported that Sandworm has adopted fake CAPTCHA prompts and Ethereum-based command infrastructure, marking a significant evolution in the group’s cyberattack techniques and making disruption considerably more difficult.

Blockchain Infrastructure Complicates Defensive Measures

Investigators said one of the campaign’s most significant innovations is its use of Ethereum smart contracts to store C2 server addresses. Unlike conventional cyber operations that rely on registered domains or centralized hosting services, blockchain-based smart contracts cannot be easily removed, altered, or disabled through legal or administrative action.

CERT-UA explained that the attackers employed a custom tool known as SMARTAXE, which retrieves updated C2 addresses through read-only Ethereum network queries. This enables operators to redirect infected systems to new servers almost immediately while preventing defenders from disabling the underlying blockchain infrastructure. Security teams are therefore left with the challenging task of identifying and blocking outbound requests to Ethereum Remote Procedure Call (RPC) endpoints that have been intentionally designed to resemble normal content delivery network traffic.

The advisory also noted that the attackers used Cloaking.House, a commercial traffic-filtering service that presents different website content depending on the visitor. As a result, automated security scanners often encounter harmless web pages, while intended victims receive malicious CAPTCHA prompts. CERT-UA advised that any website serving such content should be considered fully compromised, potentially through stolen administrator credentials, vulnerable content management systems, malicious plugins, or web shells.

Multi-Platform Malware Targets Windows and Android

Once a victim executes the malicious PowerShell command, a multi-stage infection sequence begins. Initial malware establishes persistence on Windows systems, followed by reconnaissance tools that collect information on hardware, installed software, browser data, and local files. Based on the collected intelligence, attackers selectively deploy additional malware families that provide persistent remote access and facilitate lateral movement within compromised networks.

The campaign also relies on legitimate administration tools, including OpenSSH and Tor, to blend malicious activity with routine network traffic. Additional modules target stored conversations from messaging applications such as Signal and WhatsApp, while stolen information is transferred using standard file synchronization utilities.

The operation deploys a layered malware framework targeting both Windows and Android devices, combining reconnaissance, persistent remote access, credential theft, messaging data collection, and cloud-based data exfiltration.

CERT-UA further identified Android malware known as COWARDDUCK, which is distributed through messaging applications disguised as security or antivirus software. Once installed, the malware collects contacts, real-time geolocation information, and files from commonly used device folders, including documents, downloads, photographs, and archives. The stolen information is transmitted through the Dropbox API, while commands are received from attacker-controlled servers and selected Steam Community pages, allowing malicious communications to blend with legitimate internet traffic.

The agency observed that the latest campaign represents a strategic shift from Sandworm’s earlier reliance on trojanized software installers distributed through torrent platforms. By embedding fake CAPTCHA prompts into compromised websites, the attackers significantly expand their potential victim pool beyond individuals downloading unauthorized software.

CERT-UA Urges Stronger Web Security Measures

CERT-UA urged website administrators to audit web infrastructure for unauthorized scripts, compromised plugins, and server-side backdoors while enforcing multi-factor authentication and rotating administrative credentials. The agency also recommended monitoring outbound connections for unusual traffic directed toward Ethereum RPC services and cloud storage platforms.

CERT-UA emphasized that no legitimate website, browser, or CAPTCHA service will ever instruct users to open a command prompt or system terminal and execute commands, warning that any such request should be treated as an active cyberattack and ignored immediately.

Previous Post

NodeMeta Expands Web3 Vision With AI, Security, and NTE Ecosystem

Next Post

OKX Launches Tokenized US Stocks and ETFs for Global Investors

Related Posts

Trikon

Trikon Partners With IBVM to Build AI-Powered Bitcoin Web3 Layer

by Kelly Cromley
Aug 10, 2026
0

Web3 infrastructure provider Trikon has partnered with IBVM, a Bitcoin-based zero-knowledge Layer 2 ecosystem, in a move aimed at combining...

solana blockchain

Solana Hits 6 Million Monthly USDC Senders as Payments Surge

by Kelly Cromley
Aug 10, 2026
0

Solana has reached a new milestone in stablecoin activity, with approximately 6 million monthly USDC senders using the blockchain, highlighting...

blackrock

BlackRock Buys $896.5M in Bitcoin and Ethereum

by Kelly Cromley
Aug 10, 2026
0

BlackRock has made substantial purchases of Bitcoin and Ethereum this week, committing a combined $896.5 million to the two leading...

Bitcoin

Bitcoin Blockchain Splits as BIP-110 Enters Enforcement Phase

by Kelly Cromley
Aug 9, 2026
0

The Bitcoin blockchain split into two competing chains on Aug. 8 after nodes running BIP-110 entered a mandatory-signaling phase that...

TRON

TRON Tests Quantum-Resistant Security on Nile Testnet

by Kelly Cromley
Aug 9, 2026
0

TRON is advancing tests of post-quantum security on its Nile Testnet as it works toward becoming one of the first...

BNB Chain

BNB Chain Tests 88% TPS Boost With BEP-675 Upgrade

by Kelly Cromley
Aug 9, 2026
0

BNB Chain has reported strong performance results from BEP-675, a proposed upgrade being tested on the Binance Smart Chain testnet...

Next Post
OKX

OKX Launches Tokenized US Stocks and ETFs for Global Investors

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

Trikon
Bitcoin News

Trikon Partners With IBVM to Build AI-Powered Bitcoin Web3 Layer

by Kelly Cromley
Aug 10, 2026
solana blockchain
Market News

Solana Hits 6 Million Monthly USDC Senders as Payments Surge

by Kelly Cromley
Aug 10, 2026
blackrock
Market News

BlackRock Buys $896.5M in Bitcoin and Ethereum

by Kelly Cromley
Aug 10, 2026
Bitcoin
Bitcoin News

Bitcoin Blockchain Splits as BIP-110 Enters Enforcement Phase

by Kelly Cromley
Aug 9, 2026
TRON
Market News

TRON Tests Quantum-Resistant Security on Nile Testnet

by Kelly Cromley
Aug 9, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.