Russian Hackers Target Ukrainian IT Workers with Fake Job Offers

Russian Hackers Target Ukrainian IT Workers with Fake Job Offers

First seen 11 Aug 2026, 20:12 UTC Therecord.MediaThehackernews 71% similarity 72.6

Article Content

Browse articles
ThreatCluster

CERT-UA has reported a social engineering campaign by Russian threat actors targeting Ukrainian IT professionals. The campaign, linked to the Sandworm group (UAC-0145), involves impersonating recruiters to deliver malware. It has been active since at least May 2026, exploiting the ongoing conflict in Ukraine. The attackers aim to deceive victims into installing malicious software under the guise of job opportunities. This tactic highlights the increasing sophistication of state-sponsored cyber operations in the region. The full scope of the impact is still being assessed, but the campaign poses a significant risk to the targeted workforce. CERT-UA continues to monitor the situation and provide updates as necessary.

Key Points: • Russian threat actors are using fake job offers to target Ukrainian IT workers. • The campaign is linked to the Sandworm group, known for state-sponsored cyber operations. • CERT-UA has been monitoring this activity since at least May 2026.

ThreatCluster AI How this analysis works

Timeline

2026-05-01
Social engineering campaign begins
Russian hackers start impersonating recruiters to target Ukrainian IT professionals, delivering malware.
Therecord.Media
2026-08-10
CERT-UA issues warning
CERT-UA publicly discloses the ongoing campaign and its links to the Sandworm group.
Therecord.Media
2026-08-11
Further details disclosed
CERT-UA provides additional information about the UAC-0145 threat cluster and its tactics.
Thehackernews

Community

Browse all →

Tracked Entities in This Story