CERT-UA warned that a Sandworm-linked cluster, UAC-0145, has been impersonating recruiters and IT companies on legitimate job platforms to target Ukrainian IT professionals, particularly system administrators and other technical staff. The attackers reportedly review resumes, move conversations from job-site chat to Telegram and Zoom, and guide candidates through a fake hiring process that includes a supposed technical assessment. As part of that process, victims receive WireGuard VPN configuration files; when the connection predictably fails, they are told to install a trojanized VPN client called SopraVPN from SourceForge and a spoofed website themed to resemble Sopra Steria Bulgaria.
CERT-UA said the malicious client was built from legitimate open-source WireGuard code but altered to decrypt and execute hidden payloads embedded in VPN configuration values through a custom SymmetricKey option, using AES-256-GCM and a shuffled Base64 alphabet. On Windows, the malware uses PowerShell and a scheduled task to fetch additional payloads from the internet, while on Linux it uses curl to retrieve an executable through attacker-controlled VPN infrastructure. The activity has been ongoing since at least May 2026, and CERT-UA urged organizations—especially telecom operators and IT companies—to limit corporate access to managed devices protected by EDR and continuous monitoring.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CERT-UA publicly reported the campaign, attributed it to UAC-0145 as a Sandworm-linked cluster, and described how the modified WireGuard client decrypted and executed hidden payloads on Windows and Linux. The advisory also published file and network indicators and urged organizations to restrict corporate access to managed devices with EDR and continuous monitoring.
CERT-UA said threat cluster UAC-0145, a subcluster of UAC-0002/Sandworm, has been running a social-engineering campaign against Ukrainian IT workers and job seekers. The operation targeted system administrators and other IT specialists through legitimate job platforms and fake recruiter interactions.
As part of the campaign, attackers impersonated recruiters and HR staff, moved conversations to Telegram and Zoom, then sent WireGuard configuration files for a supposed technical test. When those files failed, victims were directed to install a malicious WireGuard-based client called SopraVPN from SourceForge via a spoofed Sopra Steria-themed website.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
news.risky.biz
Open sourcebleepingcomputer.com
Open sourcetrojan-killer.net
Open sourcetherecord.media
Open sourcecert.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.