According to Ukraine's Computer Emergency Response Team (CERT-UA), on July 19, 2026, the agency disclosed a sophisticated cyberattack campaign attributed to UAC-0145, a subgroup of Russian military intelligence-linked Sandworm, that employs fake CAPTCHA prompts and Ethereum-based command infrastructure. The attackers trick users into executing malicious commands through counterfeit CAPTCHA messages on compromised websites, while using Ethereum smart contracts to store command-and-control server addresses—a technique that cannot be easily disrupted through conventional legal or administrative action.
CERT-UA identified the custom tool SMARTAXE, which retrieves updated C2 addresses via Ethereum network queries, enabling attackers to redirect infected systems almost immediately. The campaign also deploys multi-platform malware targeting Windows and Android devices, including COWARDDUCK, which collects contacts, geolocation, and files from messaging applications through the Dropbox API. CERT-UA warned that no legitimate website or CAPTCHA service will ever instruct users to execute system commands, and urged website administrators to audit infrastructure for unauthorized scripts and enforce multi-factor authentication.