Sandworm Hackers Use Fake Job Interviews to Deploy Trojanized VPN Client

Sandworm Hackers Use Fake Job Interviews to Deploy Trojanized VPN Client

First seen 11 Aug 2026, 20:12 UTC Therecord.MediaThehackernewsBleepingcomputerGbhackersCybersecuritynews+3 77.0

Article Content

Browse articles
ThreatCluster

The Russian threat group Sandworm has been targeting IT professionals through a social engineering campaign since May 2026. The campaign, attributed to the UAC-0145 subgroup, involves impersonating IT companies and recruiters to lure victims into downloading a trojanized WireGuard VPN client. Victims are approached via fake job offers, and conversations are moved to Telegram for video interviews. During these interviews, candidates receive technical assignments requiring VPN access, leading them to download a malicious client called 'SopraVPN.' This client is designed to execute embedded PowerShell code and can create scheduled tasks on Windows or retrieve executables on Linux. CERT-UA has advised IT companies to restrict access to corporate resources to managed devices. The campaign highlights the ongoing threat to critical infrastructure and government entities, particularly in Ukraine.

Key Points: • Sandworm's UAC-0145 subgroup targets IT professionals via fake job offers. • Victims are tricked into downloading a trojanized WireGuard VPN client during interviews. • CERT-UA advises restricting corporate access to managed, monitored devices.

Timeline

2026-05-01
Campaign targeting IT professionals begins
Sandworm starts a social engineering campaign targeting system administrators and IT specialists in Ukraine.
Therecord.Media
2026-08-10
CERT-UA discloses details of the campaign
The Ukrainian Computer Emergency Response Team reveals the ongoing social engineering tactics used by Sandworm.
Therecord.Media
2026-08-11
BleepingComputer reports on the trojanized VPN client
BleepingComputer details the malicious WireGuard client and its capabilities, including executing PowerShell code.
Bleepingcomputer
2026-08-11
The Hacker News confirms UAC-0145 attribution
The Hacker News reports on the social engineering campaign and its attribution to the Sandworm threat group.
Thehackernews
2026-08-12
Cybersecurity News highlights the attack method
Cybersecurity News discusses the use of fake job interviews to deploy malware and compromise IT workers.
Cybersecuritynews