CoinTrust

Ukraine Warns of Sandworm’s Blockchain-Based Cyberattack Tactics

Ukraine

Ukraine’s Computer Emergency Response Team (CERT-UA) has disclosed a sophisticated cyber campaign attributed to UAC-0145, a subgroup of the Russian military intelligence-linked Sandworm hacking operation. In an advisory issued on July 19, 2026, the agency reported that the attackers had significantly changed their tactics by relying on fake CAPTCHA prompts to trick users into infecting their own computers while concealing command-and-control (C2) infrastructure within the Ethereum blockchain.

According to CERT-UA, the campaign abandons traditional malware delivery methods that depend on software exploits or malicious email attachments. Instead, compromised websites display counterfeit CAPTCHA or error messages instructing visitors to open the Windows Run dialog or terminal, paste a command that has already been copied to the clipboard by embedded JavaScript, and execute it. Because victims unknowingly launch the malicious command themselves using legitimate system utilities, the attack can evade conventional endpoint security tools that typically monitor suspicious software installations.

CERT-UA reported that Sandworm has adopted fake CAPTCHA prompts and Ethereum-based command infrastructure, marking a significant evolution in the group’s cyberattack techniques and making disruption considerably more difficult.

Blockchain Infrastructure Complicates Defensive Measures

Investigators said one of the campaign’s most significant innovations is its use of Ethereum smart contracts to store C2 server addresses. Unlike conventional cyber operations that rely on registered domains or centralized hosting services, blockchain-based smart contracts cannot be easily removed, altered, or disabled through legal or administrative action.

CERT-UA explained that the attackers employed a custom tool known as SMARTAXE, which retrieves updated C2 addresses through read-only Ethereum network queries. This enables operators to redirect infected systems to new servers almost immediately while preventing defenders from disabling the underlying blockchain infrastructure. Security teams are therefore left with the challenging task of identifying and blocking outbound requests to Ethereum Remote Procedure Call (RPC) endpoints that have been intentionally designed to resemble normal content delivery network traffic.

The advisory also noted that the attackers used Cloaking.House, a commercial traffic-filtering service that presents different website content depending on the visitor. As a result, automated security scanners often encounter harmless web pages, while intended victims receive malicious CAPTCHA prompts. CERT-UA advised that any website serving such content should be considered fully compromised, potentially through stolen administrator credentials, vulnerable content management systems, malicious plugins, or web shells.

Multi-Platform Malware Targets Windows and Android

Once a victim executes the malicious PowerShell command, a multi-stage infection sequence begins. Initial malware establishes persistence on Windows systems, followed by reconnaissance tools that collect information on hardware, installed software, browser data, and local files. Based on the collected intelligence, attackers selectively deploy additional malware families that provide persistent remote access and facilitate lateral movement within compromised networks.

The campaign also relies on legitimate administration tools, including OpenSSH and Tor, to blend malicious activity with routine network traffic. Additional modules target stored conversations from messaging applications such as Signal and WhatsApp, while stolen information is transferred using standard file synchronization utilities.

The operation deploys a layered malware framework targeting both Windows and Android devices, combining reconnaissance, persistent remote access, credential theft, messaging data collection, and cloud-based data exfiltration.

CERT-UA further identified Android malware known as COWARDDUCK, which is distributed through messaging applications disguised as security or antivirus software. Once installed, the malware collects contacts, real-time geolocation information, and files from commonly used device folders, including documents, downloads, photographs, and archives. The stolen information is transmitted through the Dropbox API, while commands are received from attacker-controlled servers and selected Steam Community pages, allowing malicious communications to blend with legitimate internet traffic.

The agency observed that the latest campaign represents a strategic shift from Sandworm’s earlier reliance on trojanized software installers distributed through torrent platforms. By embedding fake CAPTCHA prompts into compromised websites, the attackers significantly expand their potential victim pool beyond individuals downloading unauthorized software.

CERT-UA Urges Stronger Web Security Measures

CERT-UA urged website administrators to audit web infrastructure for unauthorized scripts, compromised plugins, and server-side backdoors while enforcing multi-factor authentication and rotating administrative credentials. The agency also recommended monitoring outbound connections for unusual traffic directed toward Ethereum RPC services and cloud storage platforms.

CERT-UA emphasized that no legitimate website, browser, or CAPTCHA service will ever instruct users to open a command prompt or system terminal and execute commands, warning that any such request should be treated as an active cyberattack and ignored immediately.

Exit mobile version