Russian threat group Sandworm, tracked as UAC-0145, has been targeting system administrators since May through fake job offers impersonating IT recruiters and companies like Sopra Steria. Attackers study resumes on job sites, initiate contact, move conversations to Telegram, and conduct Zoom interviews in English where candidates receive mock technical assignments requiring VPN connections. Victims are sent WireGuard configuration files and then directed to download a trojanized client called "SopraVPN" from SourceForge to perform test tasks.
The malicious client includes a nonstandard SymmetricKey option that decrypts and executes embedded PowerShell code on Windows, creating scheduled tasks and downloading additional payloads, while Linux systems use cURL to retrieve executables through the VPN. The trojanized version replaces WireGuard's standard Base64 decoding with a custom dynamically generated alphabet to evade analysis. CERT-UA advises telecommunications and IT companies to restrict corporate resource access to managed, monitored devices protected by EDR, even for personal equipment. The campaign demonstrates Sandworm's continued focus on critical infrastructure and government entities, leveraging social engineering to gain initial access. The attackers impersonate legitimate organizations using lookalike email addresses and domains. The group is notorious for targeting Ukraine and other nations. Organizations should educate IT staff about such recruitment scams. The campaign has been ongoing since at least May 2026.
Read more...
