Cybersecurity researchers at Cisco have uncovered a sophisticated attack on a Ukrainian government organisation that they believe was orchestrated by Russian hackers. The intrusion, detected in April, used a fake Google CAPTCHA verification page to trick victims into running malicious software, according to a report released this week.
The researchers said they found a malware strain known as Amatera running on the compromised system. Amatera is designed to harvest sensitive information, including login credentials and cryptocurrency wallet data. The attackers also installed a remote access tool that allowed them to inspect files, transfer data, and execute commands on the infected machine.
According to Cisco's analysis, the malware was configured to communicate with a command-and-control server located in Russia. While the company could not confirm whether any data was actually exfiltrated or whether the attackers actively used the access, it assessed with moderate confidence that the operation was part of a broader campaign targeting Ukrainian entities and possibly other European organisations.
Fake CAPTCHA as a delivery mechanism
The initial infection vector remained unclear, but Cisco researchers discovered a malicious file named "verification.google" on the Ukrainian system. To trace the origin, they searched for similar attacks and found another infection involving the same Amatera malware. In that case, they traced the attack back to compromised websites that displayed fake Google CAPTCHA checks.
Instead of the usual prompt to tick a box or identify traffic lights, the fake CAPTCHA instructed users to open a Windows dialog box and paste a string of text. This action executed the malware on the victim's machine. The technique is particularly insidious because it exploits user trust in a familiar verification process.
In the second infection, the attackers also deployed a cryptocurrency stealer that monitored clipboard activity. When a victim copied a wallet address, the malware replaced it with an address controlled by the attackers, potentially redirecting digital currency payments. This suggests the campaign was financially motivated, though it could also serve espionage purposes.
Cisco noted that the similarities between the two infections indicate that the Ukrainian government attack likely began in the same way. The report highlights the growing sophistication of Russian cyber operations, which have increasingly targeted Ukrainian infrastructure and government networks since the full-scale invasion began in 2022.
This incident comes amid a broader pattern of hybrid attacks against European targets. Earlier this year, a former Spanish minister described a migrant surge at the Ceuta border as a hybrid attack designed to destabilise the EU. Meanwhile, Latvia has become the first EU state to ban Russian and Belarusian print imports, reflecting heightened concerns about Russian influence operations.
The Ukrainian government has been a frequent target of Russian cyberattacks, with hackers often using phishing and social engineering to breach systems. The use of fake CAPTCHA pages adds a new layer of deception, making it harder for users to detect malicious activity.
Cisco's report underscores the need for European organisations to remain vigilant against such threats. The researchers advised users to be cautious when encountering unexpected verification prompts, especially those that ask them to run commands or paste text. They also recommended implementing multi-factor authentication and regularly updating security software.
While the full scope of the attack remains unknown, the findings serve as a reminder of the persistent cyber threat posed by Russian actors. As European nations continue to support Ukraine, they must also bolster their own cyber defences against potential retaliation.


