Close Menu
NCIJ Network NCIJ Network
    What's Hot

    G-7 Agrees to Release Emergency Diesel Stockpiles to Rein in High Fuel Costs

    October 2, 2026

    French media respond to M. Le Pen’s ‘Kevlar suit’ comments against investigative outlet

    October 2, 2026

    England school inspections to be overhauled again after barrage of complaints | Schools

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • G-7 Agrees to Release Emergency Diesel Stockpiles to Rein in High Fuel Costs
    • French media respond to M. Le Pen’s ‘Kevlar suit’ comments against investigative outlet
    • England school inspections to be overhauled again after barrage of complaints | Schools
    • Netflix is pivoting away from prestige
    • Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
    • Wall Street giant BNY discusses infrastructure tie-up with Kraken parent Payward
    • Hawaii’s iconic 500-year-old Hōlei Sea Arch has collapsed into the sea
    • Europe’s Extreme Summer Triggered Cascading Climate Shocks
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 13, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 11, 2026Social Engineering / Malware

    The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware.

    CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44, Seashell Blizzard, and UAC-0002), a sophisticated hacking group affiliated with the GRU. The campaign is assessed to be ongoing since May 2026.

    “Specifically, on job search websites, after reviewing a candidate’s resume, the attackers contact a potential victim – typically a system administrator or IT specialist – on behalf of an IT company (such as ATLAS Business Group),” CERT-UA said.

    Although initial communications take place via built-in online chat, the conversation subsequently shifts to messaging apps like Telegram, where a preliminary chat takes place with a purported HR manager who claims to be in charge of the candidate screening process for Sopra Steria Bulgaria, a legitimate Europe-based consulting and software development company.

    Cybersecurity

    As part of the chat, the agency said general work-related questions and the candidates’ English language proficiency are discussed, after which they are invited to join a Zoom videoconference call.

    While the meeting does take place as expected with an English-speaking man who appears to be between 30 and 35 years old, it’s unclear whether the person showing up in the interview was a genuine participant or a synthetic persona generated using artificial intelligence (AI).

    In tandem, additional instructions for a technical interview are sent via an email. This includes configuration files for connecting to the corporate VPN using WireGuard to supposedly complete an assessment, along with a link to a second Zoom meeting during which the test is monitored.

    Should the victim attempt to connect to the VPN using the provided configuration files, they run into error messages, causing the threat actors to recommend downloading a custom VPN solution named SopraVPN hosted on SourceForge by sharing a bogus link designed to mimic Sopra Steria Bulgaria’s website (“soprasteria-bg[.]com”) –

    • sourceforge[.]net/projects/soprabulgariavpn
    • sourceforge[.]net/projects/sopravpn

    The Hacker News also identified a third SourceForge project called “sourceforge[.]net/projects/soprasteriavpn,” which claims to be an “open-source corporate VPN solution designed for businesses seeking secure remote access and site-to-site connectivity without expensive licensing fees,” according to cached Google Search results. None of these projects are available for download.

    “The essence of this trick is that the attackers’ VPN client was compiled from the WireGuard source code with a number of modifications,” CERT-UA explained. “Specifically, support for the non-standard ‘SymmetricKey’ option has been added to the configuration processing mechanism; its value contains BASE64-encoded data for AES-256-GCM: a nonce, ciphertext, and an authentication tag.”

    “A 32-byte value obtained by decoding ‘PrivateKey’ is used as the AES-256 key. The PowerShell code decrypted in this way is then passed to the standard ‘runScriptCommand’ mechanism, which WireGuard uses, in particular, to execute commands specified by the ‘PostUp’ option.”

    Put differently, the poisoned version of WireGuard allows an attacker to run arbitrary commands on the victim host without their knowledge.

    Cybersecurity

    The Windows VPN client also makes use of a PowerShell command to create a scheduled task that downloads a secondary payload from a remote URL, while the Linux variant uses cURL to download the executable file from the attackers’ infrastructure via a VPN. The exact nature of the next-stage payload is unclear.

    CERT-UA is urging IT professionals to be on the lookout for social engineering techniques to stay protected against potential malware attacks. Organizations are recommended to allow access to corporate resources only from managed devices on which appropriate security software is installed and ensure relevant policies are configured and continuous monitoring is enforced.

    The disclosure comes less than a month after the agency attributed the threat actor to another campaign that employs the ClickFix social engineering tactic to infect Ukrainian machines with data-stealing malware.

    With the latest development, Russian threat actors have joined alongside Chinese, Iranian, and North Korean adversaries in using fake recruitment campaigns to gain unauthorized access to targeted systems.

    Commands Fake interviews job Push Run SandwormLinked UAC0145 VPN
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

    On the run for 20 years, Ugandan warlord Kony still ‘active’ within the Lord’s Resistance Army

    Crypto Scammers Hijack Microsoft’s Official X Account

    Is It Fair to Blame ‘Rogue’ AI for Security Failures?

    GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

    SWIFT Banking & Government Middleware Enables RCE

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    G-7 Agrees to Release Emergency Diesel Stockpiles to Rein in High Fuel Costs

    October 2, 2026

    French media respond to M. Le Pen’s ‘Kevlar suit’ comments against investigative outlet

    October 2, 2026

    England school inspections to be overhauled again after barrage of complaints | Schools

    October 2, 2026

    Netflix is pivoting away from prestige

    October 2, 2026
    Latest Posts

    Lime bikes hurtling around the city: is this the revenge of a priced-out generation? | Andy Beckett

    August 8, 2026

    Clarity Act Delayed Until September, Trump Praises Bitcoin

    August 8, 2026

    North Carolina Ports confirms cyberattack disrupting operations

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    G-7 Agrees to Release Emergency Diesel Stockpiles to Rein in High Fuel Costs

    October 2, 2026

    French media respond to M. Le Pen’s ‘Kevlar suit’ comments against investigative outlet

    October 2, 2026

    England school inspections to be overhauled again after barrage of complaints | Schools

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.