FluidLeech is a malware loader associated with Sandworm activity, including campaigns tracked by CERT-UA as UAC-0145 targeting Ukraine in 2026. It has been observed as part of multi-stage intrusion chains delivered through ClickFix-style social engineering on compromised websites, where victims are tricked into executing malicious PowerShell commands that fetch follow-on payloads. FluidLeech has also been linked to broader Sandworm tradecraft that includes fake security-themed lures and other socially engineered delivery methods.
In reported operations, FluidLeech functioned as a loader used after initial compromise to deploy additional tooling on selected victim systems. It has been described as masquerading as antivirus or virus-removal software, indicating a deception component intended to reduce suspicion during execution. The malware appeared alongside other Sandworm tools including GHETTOVIBE, SCOUTCURL, LOADLOOP, and the Python backdoor FREAKYPOLL. Within these intrusion chains, reconnaissance and victim triage preceded the use of additional payloads for longer-term access, and FluidLeech was one of the components used when operators chose to deepen access on valuable targets.
The malware is associated with Windows-focused infection flows because the observed ClickFix chains relied on PowerShell execution and related Windows persistence and scripting mechanisms. The broader campaigns using FluidLeech were directed at Ukrainian targets and formed part of Sandworm’s sustained espionage and intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
If the target was valuable, the threat actors used other malware samples to gain persistent access to the system. For example, FluidLeech, a fake antivirus software, and LoadLoop, a loader, were also used in the attacks.
...payloads such as FLUIDLEECH, LOADLOOP, and the Python backdoor FREAKYPOLL.
Серед лоадерів також відмічено використання програмних засобів FLUIDLEECH, замаскованого під програмний засіб для видалення "вірусів"
5 distinct techniques documented for this family, organized by ATT&CK tactic.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A fake antivirus malware family used by Sandworm to help establish persistent access on systems deemed valuable.
A named payload in the UAC-0145 ClickFix infection chain; specific functionality is not described in the content.
A loader used in the campaign, masquerading as antivirus-removal software.
Malware loader used in Sandworm intrusion activity to deliver or stage additional payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.