type: entity ยท created: 2026-07-18 ยท updated: 2026-07-18 ยท tags: [apt-group, nation-state, russia, social-engineering] ยท confidence: high ยท affected_sectors: [government, technology] ยท au_impact: false
Sandworm
Russia's Sandworm APT group (also tracked as APT-44, UAC-0135, Voodoo Bear) is a unit of the Russian GRU's Main Centre for Special Technologies (GTsST).
CAPTCHA Social Engineering Campaign (July 2026)
- Observed technique: Fake CAPTCHA verification pages targeting Ukrainian users
- Lure: Victims are prompted to complete a CAPTCHA to access a website
- Payload: The CAPTCHA tricks victims into running malicious PowerShell commands
- Result: Grants attackers system-level access to the victim's machine
- Discovered by: The Record by Recorded Future (raw/digests/Cyber-Digest-2026-07-18)
This novel social engineering approach evades traditional email-based phishing detection by hosting the lure on legitimate-looking websites that use CAPTCHA as a trust signal.
Related Pages
- Cisa Acsc Russian Network Devices โ Joint advisory on Russian targeting of network infrastructure
- Operation First Light 2026 โ Large-scale anti-scam operation