GHETTOVIBE is a Visual Basic Script malware component used in Sandworm activity targeting Ukraine, particularly in campaigns attributed to the UAC-0145 cluster. It has been observed in ClickFix-style intrusion chains in which victims are lured through compromised websites displaying fake CAPTCHA or verification prompts and are tricked into executing malicious PowerShell commands on Windows systems. Those commands can download and place the script in the Windows Startup folder to establish autorun persistence.
GHETTOVIBE functions as an early-stage payload that helps attackers maintain access and enable deployment of additional tooling. It has been associated with follow-on malware and scripts including SCOUTCURL for host reconnaissance and data theft, as well as other Sandworm tooling used for longer-term access. Reported operations indicate targeting of Ukrainian organizations and other devices of interest, with the broader campaign linked to Russian state-sponsored Sandworm tradecraft.
High-confidence reporting supports GHETTOVIBE as a Windows-focused script-based malware used for persistence and post-compromise enablement rather than as a standalone destructive payload. Its role in the intrusion chain is to survive reboots via Startup-folder placement and support subsequent malicious activity on infected hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For example, the GHETTOVIBE Visual Basic script has been seen attempting to self-perpetuate by storing itself in the Windows Startup folder.
CERT-UA described one command pattern that downloads and stores a VBS file in the Startup autorun directory. One observed variant was named GHETTOVIBE.
...завантаження та збереження в каталозі автозапуску Startup VBS-файлу; один з варіантів такої програми отримав назву GHETTOVIBE.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The command downloads malware that allows hackers to maintain access to the computer and deploy additional malicious tools later.
CERT-UA researchers found ten websites hosting CAPTCHA pages that redirected users to web pages with malicious PowerShell commands.
The commands downloaded Visual Basic scripts and other malicious files, which in turn deployed several malware families known to be used by Sandworm.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Visual Basic script used in the intrusion chain that attempts persistence by copying itself into the Windows Startup folder.
A VBS-based payload/loader delivered via ClickFix-style PowerShell commands and persisted in the Startup folder.
A VBS-based data-stealing malware variant delivered via ClickFix-style social engineering and placed in the Startup autorun directory for persistence.
Backdoor malware used to maintain access on compromised systems and enable deployment of additional malicious tools.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.