Close Menu
NCIJ Network NCIJ Network
    What's Hot

    August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

    August 11, 2026

    This spot Bitcoin ETF only logged six inflow days ever

    August 11, 2026

    Cambodia’s banned sand trade with Singapore appears to be back

    August 11, 2026
    Facebook X (Twitter) Instagram
    Trending
    • August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
    • This spot Bitcoin ETF only logged six inflow days ever
    • Cambodia’s banned sand trade with Singapore appears to be back
    • American Oversight Launches Investigation, Demands Records Preservation at Interior Department Following Allegations of Routine Document Destruction, Signal Use
    • Illinois farmers saw nation’s biggest jump in seasonal planting diesel costs, analysis finds
    • Why AI Is More Popular in China Than the United States
    • Australia politics live: Coalition to heavily cut net migration and shred 96% of house construction code; CBA posts bumper $11bn profit | Australian politics
    • Hard work or humour? Take the British values quiz | Social trends
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 11
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Sandworm hackers target IT pros with trojanized WireGuard VPN client

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 11, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May.

    A report from the Ukrainian Computer Emergency Response Team (CERT) details a social engineering campaign attributed to UAC-0145, which is believed to be a sub-cluster of Sandworm (APT44). In the campaign, the threat actor targets victims while posing as IT companies and recruiters.

    The agency says that the attacker studies the targets’ resumes uploaded on job sites and then initiates direct contact.

    image

    Conversations are then moved to Telegram to arrange a video interview over Zoom. During the interview, which is conducted in English, the candidates receive mock technical assignments that require them to connect to a corporate VPN.

    Conversations with a supposed recruiter
    Conversations with a supposed recruiter
    Source: CERT-UA

    In one case that CERT-UA observed, the attacker impersonated the international IT firm Sopra Steria using seemingly legitimate email addresses similar to the company’s office in Bulgaria.

    “In parallel, additional instructions for the technical interview are sent via email, including configuration files for connecting to a ‘corporate’ VPN using Wireguard (Linux/Windows) to supposedly perform test tasks,” CERT-UA says.

    Email-download
    Malicious emails and VPN download link
    Source: CERT-UA

    The downloaded file is configured to produce a fake error. The attackers then prompt the victim to download a modified WireGuard-based client called “SopraVPN” from SourceForge.

    The SourceForge page even includes a link to soprasteria-bg[.]com to increase credibility, although the domain has no connection to the legitimate company.

    The trojanized client supports a malicious, nonstandard “SymmetricKey” configuration option that decrypts and executes embedded PowerShell code.

    On Windows, the malicious command creates a scheduled task and downloads an additional payload from the Internet.

    On Linux, it uses cURL to retrieve another executable from attacker-controlled infrastructure through the VPN.

    CERT-UA also noted that WireGuard’s standard Base64 decoding was replaced in the trojanized version with a custom, dynamically generated Base64 alphabet, which renders key strings unreadable with standard decoders and protects the PowerShell code from analysis.

    The Ukrainian cyber agency advises telecommunications providers and IT companies whose staff are targeted by this campaign to restrict corporate resource access to managed, continuously monitored devices protected by EDR, including when employees use personal equipment.

    APT44 is notorious for targeting critical infrastructure and government entities both in Ukraine, and also in other countries.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    client hackers pros Sandworm Target Trojanized VPN WireGuard
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

    Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees

    Cisco warns of ASA and FTD VPN flaw exploited to crash devices

    Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

    Windows 11 KB5121003 & KB5120240 cumulative updates released

    OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

    August 11, 2026

    This spot Bitcoin ETF only logged six inflow days ever

    August 11, 2026

    Cambodia’s banned sand trade with Singapore appears to be back

    August 11, 2026

    American Oversight Launches Investigation, Demands Records Preservation at Interior Department Following Allegations of Routine Document Destruction, Signal Use

    August 11, 2026
    Latest Posts

    I grew up near Andy Burnham. This is what shaped our new PM | Andy Burnham

    July 25, 2026

    The Economic Philosophy of Britain’s Andy Burnham

    July 25, 2026

    Samsung Wallet Will Add Stablecoin Support, Including USDC

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

    August 11, 2026

    This spot Bitcoin ETF only logged six inflow days ever

    August 11, 2026

    Cambodia’s banned sand trade with Singapore appears to be back

    August 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.