← All stories
● Covered by 3 sources · 3 reportsMedium impact3 negative

Russian Sandworm Hackers Target Ukrainian IT Workers with Malicious VPNs via Fake Job Offers

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Sandworm (UAC-0145) targets Ukrainian IT workers.
  • Hackers pose as recruiters on job sites.
  • Campaign uses fake job offers and interviews.
  • Victims are tricked into installing malicious VPN clients.
  • Malware allows command execution and further compromise.

Overview of the Campaign

Russian military intelligence hackers, known as Sandworm and tracked as UAC-0145, are conducting a social engineering campaign targeting Ukrainian IT professionals. The operation, active since at least May, involves the attackers posing as recruiters to trick victims into installing malicious software.

The primary goal is to compromise the computers of system administrators and other IT workers by having them download a modified VPN application during a fabricated recruitment process. This malicious VPN client can execute commands on the victim's system or download additional payloads.

Recruitment Tactics

The hackers search legitimate Ukrainian job sites for potential victims, reviewing their resumes before making initial contact. Communications typically begin through the job website's built-in chat, then move to messaging apps like Telegram.

In one observed case, the attackers claimed to represent a recruitment company called Atlas Business Group and stated they were hiring for a project involving Sopra Steria Bulgaria, a legitimate international IT services company. A fake HR manager conducts an initial screening, followed by a video interview over Zoom.

Malware Delivery

During the fake interview process, candidates receive mock technical assignments that require them to connect to a 'corporate' VPN. Instructions for the technical interview are sent via email, including configuration files for connecting to a VPN using WireGuard (for Linux/Windows).

This trojanized WireGuard VPN client is designed to execute PowerShell code or download further malicious payloads, thereby compromising the victim's system. The campaign highlights an evolving tactic by state-sponsored actors to infiltrate IT infrastructure through personnel.

Attribution and Impact

Ukraine’s computer emergency response team, CERT-UA, attributed the campaign to Sandworm, a notorious hacking unit associated with Russia’s GRU military intelligence agency. CERT-UA tracks the specific cluster of activity as UAC-0145, which is considered a subgroup of Sandworm (also known as APT44, Seashell Blizzard, and UAC-0002).

The targeting of IT professionals, particularly system administrators, indicates an effort to gain access to critical IT infrastructure. Compromising these individuals could provide attackers with elevated privileges and access to sensitive networks.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The Russian threat group Sandworm is targeting system administrators and IT professionals with fake job offers to distribute a trojanized WireGuard VPN client. This campaign, identified by CERT-UA, uses social engineering to trick victims into installing malicious software that executes PowerShell code or downloads further payloads, compromising their systems.

CERT-UA reports that the Russian threat group UAC-0145, a subgroup of Sandworm, is targeting Ukrainian IT workers with a social engineering campaign. Attackers pose as recruiters to trick victims into installing a malicious VPN client that can execute commands on their systems. This campaign highlights an evolving tactic by state-sponsored actors to compromise IT infrastructure through personnel.

Russian military intelligence hackers, identified as Sandworm, are posing as recruiters on Ukrainian job sites to trick IT professionals into installing malicious software. This campaign, active since at least May, aims to compromise the computers of system administrators and other IT workers by having them download a modified VPN application during a fake recruitment process.