Back to news

Sandworm Deploys CAPTCHA Trick on Ukraine; Microsoft Fixes Record 570 Flaws

A GRU-linked hacking unit is weaponizing fake CAPTCHAs against Ukrainian targets while Microsoft rushes out its largest-ever patch batch, nearly tripling last month's record.

Sandworm Deploys CAPTCHA Trick on Ukraine; Microsoft Fixes Record 570 Flaws

What happened

Russia's GRU-affiliated Sandworm group, acting through a sub-cluster designated UAC-0145, has been running a campaign that uses fraudulent ClickFix CAPTCHA prompts to manipulate Ukrainian users into manually executing malware on their own machines. Ukraine's national cyber defense body, CERT-UA, confirmed the attribution and warned that the payloads are designed to exfiltrate sensitive data. Separately, Microsoft's July Patch Tuesday addressed at least 570 distinct security vulnerabilities across Windows and related software — nearly three times the volume patched just the prior month. The company credited AI-assisted vulnerability research as a primary driver behind the swelling discovery rates.

Why it matters for your business

The ClickFix technique is not confined to conflict zones: it has been adapted by multiple threat actors globally and requires no sophisticated exploit — only a user who follows an on-screen instruction. Any organization relying on standard endpoint defenses without layered user-awareness training is exposed. Meanwhile, Microsoft's ballooning patch volumes represent an acute operational burden; 570 fixes in a single cycle demands a disciplined, risk-prioritized patching workflow rather than a blanket 'apply when convenient' policy. Security teams should immediately triage this month's release for critical and zero-day items and treat unpatched Windows environments as actively at risk.

What to watch next

The UAC-0145 campaign is likely to evolve its social-engineering lures beyond Ukrainian targets as the ClickFix template gains traction among other state and criminal actors. On the patching front, if AI-assisted discovery continues at its current pace, monthly patch volumes could become structurally larger — forcing enterprises to reconsider how vulnerability management is staffed and automated. Organizations should monitor CERT-UA advisories and Microsoft's Security Update Guide for emerging indicators and priority guidance.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp