SopraVPN is a trojanized VPN client built from modified WireGuard source code and used in a Sandworm-linked social-engineering campaign tracked as UAC-0145, also associated with APT44 and Seashell Blizzard. The malware has been used against system administrators and other IT professionals, particularly in Ukraine, through fake recruitment workflows that impersonate employers and culminate in a supposed technical assessment requiring VPN access.
The infection chain relies on recruiter-themed lures delivered through job-platform messaging, Telegram conversations, email instructions, and live interview interactions. Victims are provided malicious WireGuard configuration files and, after expected connection failures, are directed to install SopraVPN as a custom client. This installation is the key compromise step.
SopraVPN alters normal WireGuard behavior by accepting an additional configuration parameter, SymmetricKey, and using that value together with the configuration private key to decrypt embedded malicious code. On Windows, the decrypted payload is PowerShell that establishes persistence via a scheduled task and retrieves an additional payload from the internet. On Linux, the malware uses command-line retrieval to download and execute another payload through the VPN channel. The modified client also changes expected Base64 key-decoding behavior to support the malicious workflow.
The operation is notable because it targets personnel with privileged access to enterprise networks and remote-access infrastructure, increasing the likelihood of follow-on intrusion, post-compromise access, and broader enterprise impact. Telecommunications and IT organizations are especially relevant target environments due to the roles being impersonated and the access levels sought from victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
When the connection predictably fails, the interviewer recommends a tailored VPN client called SopraVPN from a project page linked by the fake company site. The application is a modified build based on WireGuard source code.
When the connection predictably fails, the interviewer recommends a tailored VPN client called SopraVPN from a project page linked by the fake company site. The application is a modified build based on WireGuard source code.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The application is a modified build based on WireGuard source code. CERT-UA found that the altered client accepts an extra configuration setting, SymmetricKey.
Sandworm has turned the routine job interview into a route for compromising IT workers.
additional instructions for the technical interview are sent via email, including configuration files for connecting to a 'corporate' VPN using Wireguard
The operation targets system administrators and other IT specialists after attackers study their resumes on job-search sites. It begins with a message from a supposed employer, moves into a chat... Early exchanges take place through a job-site chat and Telegram
On Windows, that code creates a scheduled task and downloads an additional payload from the internet.
On Windows, the malicious command creates a scheduled task and downloads an additional payload from the Internet.
The key clue is a non-standard SymmetricKey option... the decrypted result is passed into WireGuard’s command-execution path used for options such as PostUp.
It uses information hidden there, together with the configuration’s private key, to decrypt embedded PowerShell code.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious modified WireGuard-based VPN client used in Sandworm-linked fake job interview campaigns. It accepts an extra configuration setting ('SymmetricKey'), uses it with the configuration private key to decrypt embedded PowerShell, creates persistence via a scheduled task on Windows, and downloads additional payloads. On Linux, it uses curl to retrieve another executable from attacker-controlled infrastructure through the VPN.
A trojanized VPN client delivered through fake job interviews. It is a modified WireGuard-based application that accepts an extra configuration setting ('SymmetricKey') to decrypt embedded PowerShell code, establishes persistence via a scheduled task on Windows, and downloads additional payloads; the Linux variant retrieves another executable via curl from attacker-controlled infrastructure through the VPN.
A malicious custom VPN application masquerading as a legitimate corporate VPN client. It was built from legitimate WireGuard open-source code but modified so malicious commands could be covertly executed on the victim’s device, with some commands encrypted and embedded in VPN configuration files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.