Thehackernews
Russian Hackers Target Ukrainian IT Workers with Fake Job Offers
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
CERT-UA has reported a social engineering campaign by Russian threat actors targeting Ukrainian IT professionals. The campaign, linked to the Sandworm group (UAC-0145), involves impersonating recruiters to deliver malware. It has been active since at least May 2026, exploiting the ongoing conflict in Ukraine. The attackers aim to deceive victims into installing malicious software under the guise of job opportunities. This tactic highlights the increasing sophistication of state-sponsored cyber operations in the region. The full scope of the impact is still being assessed, but the campaign poses a significant risk to the targeted workforce. CERT-UA continues to monitor the situation and provide updates as necessary.
Key Points: • Russian threat actors are using fake job offers to target Ukrainian IT workers. • The campaign is linked to the Sandworm group, known for state-sponsored cyber operations. • CERT-UA has been monitoring this activity since at least May 2026.