UAC-0145 (Sandworm sub-cluster) uses ClickFix CAPTCHA lures against Ukrainian targets
CERT-UA attributes a fresh ClickFix campaign to UAC-0145, a sub-cluster of the Russian GRU-linked Sandworm group, tricking targets into pasting a malicious command into Win+R to self-install a credential/data stealer. It's the same clipboard-hijack social-engineering shape this watch has flagged in commodity infostealer campaigns (ACR Stealer) this week, now with a state-actor byline — the technique has fully crossed from crimeware into APT tradecraft. Nothing here touches package registries directly; filed as context for anyone tracking ClickFix as a recurring initial-access vector rather than as a supply-chain compromise in its own right.