Published: · Region: Eastern Europe · Category: cyber

CONTEXT IMAGE
Person employed to protect properties or people
Context image; not from the reported event. Photo via Wikimedia Commons / Wikipedia: Security guard

Russian State Hackers Turn Fake CAPTCHAs and VPN Zero‑Days Into New Front Against Ukraine and Its Allies

Security researchers say a Russian state-backed group is using bogus CAPTCHA checks and fake security apps to infect Ukrainian Windows and Android devices, while another campaign exploited previously unknown SonicWall VPN flaws to gain root access. The operations show how Moscow is trying to burrow into the networks that support Ukraine and its partners, turning routine clicks and remote access tools into weapons.

On Ukraine’s digital front line, even a simple “I am not a robot” box can now be a trap laid by a state-backed hacking unit.

Security researchers have disclosed that a Russian state-linked group identified as UAC-0145 is running an attack campaign that uses fake CAPTCHA checks to trick Ukrainian targets into executing malware on Windows systems. The same operation reportedly deploys bogus security applications to backdoor Android devices. When users think they are completing routine verification or installing protection, they are in fact granting attackers access deep into their devices.

The group’s activity is part of a broader pattern in which Russian cyber units pivot from blunt, disruptive attacks to more insidious, credential-stealing and surveillance-focused operations. By compromising both desktop and mobile endpoints, UAC-0145 can potentially monitor communications, exfiltrate sensitive data and stage follow-on attacks inside critical networks connected to Ukraine’s government, military or essential services. The specific victims in this wave have not been named, but the targeting focus on Ukrainian users underscores the campaign’s wartime role.

In a separate but equally consequential development, researchers said two zero-day vulnerabilities in SonicWall SMA 1000 series devices were exploited in the wild before being publicly disclosed. The flaws allowed attackers to gain root access to the appliances, which are widely used as secure remote access gateways in corporate and government environments. The malicious activity has been linked to an actor tracked as UTA0533, which is reported to have planted custom malware and captured unencrypted LDAP credentials from compromised VPN devices.

For system administrators and CISOs in Ukraine and allied countries, these revelations land with particular weight. SonicWall appliances often sit at the edge of sensitive networks, controlling who can log in remotely. A successful compromise at that layer lets intruders bypass many of the internal defenses organizations rely on, potentially granting them near-complete visibility and control inside ministries, military offices, or private firms supporting defense logistics and reconstruction.

For frontline staff and ordinary users, the threat is more mundane but no less real. A hurried click on a CAPTCHA during a long workday, or the installation of what appears to be a helpful security app to keep a personal phone safe, can now open a doorway to adversaries tied to a foreign intelligence service. In a country already under kinetic attack, the idea that phones and laptops can quietly become sensors for the enemy raises anxiety and complicates everyday digital life.

Strategically, these campaigns highlight the evolution of Russia’s cyber posture in its war against Ukraine and in its broader confrontation with the West. Rather than focusing solely on high-visibility power-grid attacks or data wipers, Russian-linked actors are investing in stealth, persistence and access to the tools that underpin modern remote work. Exploiting zero-days in widely deployed VPN products suggests they are looking not just at Ukrainian networks, but at the multinational ecosystem of contractors, NGOs and allied institutions that interact with them.

The shareable insight is straightforward: Moscow no longer needs to breach the front gate of a ministry to spy on it – it can often slip in through the VPN box or the CAPTCHA window that staff treat as background noise.

In the coming period, key signals will include how quickly organizations in Ukraine and partner states patch or replace vulnerable SonicWall devices, whether new indicators of compromise are shared widely enough to blunt UAC-0145’s and UTA0533’s reach, and if additional Russian-linked campaigns emerge targeting other remote access tools. Public guidance from Western and Ukrainian cyber authorities on these specific threats, or broader moves to harden critical digital infrastructure tied to the war effort, will show how seriously capitals are taking this quieter but strategically significant front.

Sources