HackMyIP
← Back to News
2026-08-11 The Hacker News

Sandworm UAC-0145 Targets Ukrainian IT Workers With Fake Job Interviews

APTMalwarePhishing

Ukraine's Computer Emergency Response Team (CERT-UA) has disclosed an ongoing social engineering campaign by Russian state-aligned threat cluster UAC-0145, a subgroup within the notorious Sandworm unit (also tracked as APT44, Seashell Blizzard, and UAC-0002) tied to the GRU. Active since May 2026, the operation impersonates recruiters from legitimate firms such as ATLAS Business Group and Sopra Steria Bulgaria on job search platforms, targeting system administrators and IT specialists with realistic hiring workflows that span Telegram chats, Zoom interviews, and follow-up emails.

Victims who pass initial screening are sent WireGuard VPN configuration files for a supposed technical assessment. When the connections fail, attackers direct candidates to download a malicious client called SopraVPN, distributed through SourceForge projects mimicking the real company at lookalike domains like soprasteria-bg[.]com. Anyone considering the legitimacy of these domains should run a WHOIS lookup to verify registrant details, and evaluate any VPN offering with a VPN/proxy detector to confirm it isn't masking command-and-control traffic. CERT-UA confirmed the client was compiled from open-source WireGuard code with a non-standard "SymmetricKey" option added, enabling remote command execution on the victim's machine.

A notable twist is uncertainty over whether the English-speaking male "interviewer" on Zoom is a real operator or an AI-generated synthetic persona, underscoring how deepfake-assisted hiring fraud is becoming a viable tactic for espionage-grade APTs. Security teams should treat unsolicited job-related VPN configuration files and SourceForge-hosted corporate clients as high-risk indicators, monitor outbound traffic from WireGuard-based applications, and educate recruiters and contractors about impersonation campaigns. Job seekers can further protect themselves by checking recruiter email addresses with an email breach checker to flag compromised or spoofed contact details before engaging further.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Auth Check →Email Breach Check →VPN & Proxy Detector →

Related Guides

Learn the background behind this story:

How phishing attacks work →How to check if an email is safe →SPF, DKIM & DMARC explained →