Russian state-sponsored attackers, specifically the UAC-0145 sub-cluster within Sandworm, have been using the ClickFix tactic to deceive Ukrainian targets into installing malware on their devices. This strategy involves presenting users with CAPTCHAs that, when solved, ultimately lead to the infection of their machines with data-stealing malware. The Computer Emergency Response Team of Ukraine (CERT-UA) has attributed this activity to UAC-0145, a group affiliated with Russia's GRU1. The use of such tactics by state-sponsored actors shifts the threat model from traditional cybercrime to a geopolitical one, requiring a distinct approach to mitigation. This development is particularly concerning, as it highlights the evolving nature of state-aligned cyber threats. The fact that UAC-0145 is leveraging social engineering tactics like ClickFix to infect devices underscores the importance of vigilance and robust security measures. So what matters to practitioners is that they must adapt their defenses to account for the unique characteristics of state-sponsored attacks, which can be more sophisticated and targeted than traditional cybercrime.