CERT-UA Exposes Sandworm-Linked UAC-0145 Fake Job Interview Campaign Spreading VPN Malware
This digest was compiled by AI from multiple sources — links to the originals are below.

Ukraine’s CERT-UA on Tuesday disclosed a months-long social engineering campaign by the Russian state-sponsored group UAC-0145, linked to Sandworm, that targets IT workers with fake job interviews to install malicious VPN software. The attackers, posing as recruiters for ATLAS Business Group and Sopra Steria Bulgaria, moved conversations to Telegram, conducted Zoom interviews—potentially with an AI persona—and directed victims to download a modified WireGuard client from SourceForge that can execute commands. The campaign has been active since May 2026.
The Social Engineering Ruse
CERT-UA attributed the activity to UAC-0145, a subgroup within Sandworm, which has been targeting Ukrainian system administrators and IT specialists since May 2026. Attackers initiate contact on job search websites, posing as recruiters from ATLAS Business Group, before moving conversations to Telegram. A supposed HR manager screens candidates, discussing general qualifications and English proficiency, then invites them to a Zoom video call with an English-speaking man. CERT-UA noted it is unclear whether the interviewer was a real person or an AI-generated persona. After the initial interview, victims receive an email with WireGuard VPN configuration files and instructions for a technical assessment, along with a second Zoom link.
The Modified WireGuard Client
When victims attempt to connect using the provided configurations, they encounter errors, prompting attackers to recommend downloading a custom VPN called SopraVPN from SourceForge. The download links were hosted on bogus websites mimicking Sopra Steria Bulgaria, such as soprasteria-bg[.]com. CERT-UA found three related SourceForge projects—soprabulgariavpn, sopravpn, and soprasteriavpn—none of which are currently available. The malicious VPN client was compiled from legitimate WireGuard source code but modified to allow command execution on the victim's machine. According to cached Google Search results, the projects claimed to be an open-source corporate VPN solution with no licensing fees.
Ongoing Threat
The campaign remains active, with CERT-UA warning that similar tactics could target other sectors beyond IT. Sandworm, also known as APT44 and Seashell Blizzard, is a GRU-linked group implicated in previous disruptive attacks on Ukraine's critical infrastructure. The use of AI-generated personas and legitimate communication platforms complicates detection. Ukrainian cybersecurity officials have not disclosed the number of victims or the scope of compromise.
What's Next
CERT-UA has urged IT professionals to remain vigilant and verify the identity of recruiters before downloading software. It remains unclear how many organizations have been compromised and whether the attackers plan to expand their targeting to other countries.
2 sources
CERT-UA Exposes Sandworm-Linked UAC-0145 Fake Job Interview Campaign Spreading VPN Malware



