Russian military hackers are posing as recruiters to target Ukrainian IT workers with malware disguised as a company VPN tool. CERT-UA says the campaign has run since at least May 2026 and is linked to Sandworm, also known as APT44 or Seashell Blizzard. Attackers contact candidates through Ukrainian job sites, move conversations to Telegram and Zoom, then send a fake technical test that requires installing a modified WireGuard-based app called SopraVPN from SourceForge and a spoofed Sopra Steria-themed site.
Why it matters: System administrators and other IT staff are being targeted through realistic job lures, which could give attackers a foothold inside sensitive environments. Ukrainian organizations and job seekers should treat recruiter messages, VPN setup files, and interview software requests with caution and verify them through trusted company channels.
Bill Toulas
2026.08.11
97% relevant
This article reports the same CERT-UA campaign and adds concrete delivery details, including the use of a trojanized WireGuard-based 'SopraVPN' client distributed via fake job interviews, Telegram coordination, SourceForge hosting, and Windows/Linux payload behavior.
info@thehackernews.com (The Hacker News)
2026.08.11
96% relevant
This appears to be the same underlying CERT-UA-reported campaign: Sandworm-linked UAC-0145 using fake job interview lures aimed at Ukrainian IT specialists to deliver a malicious SopraVPN package that enables command execution and follow-on compromise.
2026.08.10
100% relevant
This article establishes a distinct CERT-UA-attributed Sandworm campaign using fake recruiter outreach and a trojanized VPN app to compromise Ukrainian IT workers; no existing tracked story covers this specific operation.
← Back to all stories