UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Ukrainian Devices Infected with Malware via ClickFix CAPTCHAs

In a disturbing example of the dark side of artificial intelligence, Ukrainian users have been targeted by a sophisticated malware campaign that exploits ClickFix CAPTCHAs. These seemingly innocuous images are actually being used to deliver malicious payloads, leaving thousands of devices compromised.

The malware in question is linked to an AI-driven vulnerability scanner called UAC-0145, which has been secretly scanning for vulnerabilities on the internet and exploiting them with precision. It’s a cat-and-mouse game between cybersecurity experts and the developers behind such tools, but this particular case takes it to a new level. By using CAPTCHAs, typically employed as an anti-spam measure to verify human users, UAC-0145 has effectively bypassed traditional security defenses.

The way this works is through an AI-powered algorithm that deciphers the CAPTCHA image and uses its output to trigger the malware’s payload delivery mechanism. This process happens in a matter of milliseconds, making it virtually undetectable by human eyes. In essence, UAC-0145 has turned what was meant to be a security safeguard into an attack vector.

The affected devices are primarily located in Ukraine, where the malware campaign seems to have been concentrated. However, given the sophistication and reach of this AI-driven tool, it’s likely that the threat is not limited to this region alone. As AI-powered vulnerability scanning tools become increasingly prevalent, we can expect to see more instances like this.

The implications are far-reaching: if an AI model capable of deciphering CAPTCHAs can compromise thousands of devices in a matter of days, what does it say about the security posture of our online infrastructure? This raises serious questions about the effectiveness of current cybersecurity measures and highlights the need for a paradigm shift in how we approach threat detection.

To stay ahead of threats like UAC-0145, users should be aware that their vulnerability scanners are not as secure as they thought. They should consider implementing AI-driven security solutions that can detect anomalies and respond to threats in real-time. This may include adopting more advanced CAPTCHA alternatives or integrating machine learning-based threat detection tools into their security protocols.

Ultimately, this incident serves as a stark reminder of the importance of keeping pace with emerging technologies – not just in terms of vulnerabilities, but also in terms of the potential for AI-powered attacks to exploit them.


Source: The Hacker News — 2026-07-19