Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-18 ยท updated: 2026-07-18 ยท tags: [apt-group, nation-state, russia, social-engineering] ยท confidence: high ยท affected_sectors: [government, technology] ยท au_impact: false

Sandworm

Russia's Sandworm APT group (also tracked as APT-44, UAC-0135, Voodoo Bear) is a unit of the Russian GRU's Main Centre for Special Technologies (GTsST).

CAPTCHA Social Engineering Campaign (July 2026)

  • Observed technique: Fake CAPTCHA verification pages targeting Ukrainian users
  • Lure: Victims are prompted to complete a CAPTCHA to access a website
  • Payload: The CAPTCHA tricks victims into running malicious PowerShell commands
  • Result: Grants attackers system-level access to the victim's machine
  • Discovered by: The Record by Recorded Future (raw/digests/Cyber-Digest-2026-07-18)

This novel social engineering approach evades traditional email-based phishing detection by hosting the lure on legitimate-looking websites that use CAPTCHA as a trust signal.

Related Pages