Poisoned WireGuard-derived VPN client used to run commands on victim hosts
Malware Activity
Summary
Hide ▲
Show ▼
A poisoned WireGuard-derived VPN client now enables arbitrary command execution and payload downloads on victim hosts, expanding a recruiter-lure operation into direct malware delivery. The modified client is distributed as SopraVPN through fake SourceForge projects and a bogus website. Its configuration handling adds a non-standard SymmetricKey option that decrypts embedded PowerShell before execution. The Windows build can create a scheduled task, while the Linux build uses cURL to fetch a secondary executable.
Related Happenings
Sandworm fake recruiter campaign targeting Ukrainian IT workers
Campaign
H score32
First: 11.08.2026 21:36
Last: 11.08.2026 21:36
Sources 1
How related:
"Specifically, on job search websites, after reviewing a candidate's resume, the attackers contact a potential victim – typically a system administrator or IT specialist – on behalf of an IT company (such as ATLAS Business Group),"
About this happening:
CERT-UA says UAC-0145, a cluster linked to Sandworm (APT44), has run a fake recruiter campaign against system administrators and IT professionals in Ukraine si...
Sandworm fake recruiter campaign targeting Ukrainian IT workers
CampaignHow related: "Specifically, on job search websites, after reviewing a candidate's resume, the attackers contact a potential victim – typically a system administrator or IT specialist – on behalf of an IT company (such as ATLAS Business Group),"
About this happening: CERT-UA says UAC-0145, a cluster linked to Sandworm (APT44), has run a fake recruiter campaign against system administrators and IT professionals in Ukraine si...
Timeline
-
11.08.2026 21:36 2 articles · 13d ago
Poisoned WireGuard-derived VPN client used to run commands on victim hosts
Initial DisclosureVictims were steered from a failed WireGuard connection to a fake SopraVPN installer hosted on SourceForge. The altered client then decrypted embedded PowerShell and used WireGuard's execution path to run attacker commands.
Show sources
- Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands — thehackernews.com — 11.08.2026 21:36
- Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands — thehackernews.com — 11.08.2026 21:36