Find notable cyber news and cases, enriched with sources, timelines, and signals.

Poisoned WireGuard-derived VPN client used to run commands on victim hosts

Malware Activity
First reported
Last updated
Happening score
H score 20
1 unique sources, 1 articles

Summary

Hide ▲

A poisoned WireGuard-derived VPN client now enables arbitrary command execution and payload downloads on victim hosts, expanding a recruiter-lure operation into direct malware delivery. The modified client is distributed as SopraVPN through fake SourceForge projects and a bogus website. Its configuration handling adds a non-standard SymmetricKey option that decrypts embedded PowerShell before execution. The Windows build can create a scheduled task, while the Linux build uses cURL to fetch a secondary executable.

Related Happenings

Sandworm fake recruiter campaign targeting Ukrainian IT workers

Campaign
H score32 First: 11.08.2026 21:36 Last: 11.08.2026 21:36 Sources 1

How related: "Specifically, on job search websites, after reviewing a candidate's resume, the attackers contact a potential victim – typically a system administrator or IT specialist – on behalf of an IT company (such as ATLAS Business Group),"

About this happening: CERT-UA says UAC-0145, a cluster linked to Sandworm (APT44), has run a fake recruiter campaign against system administrators and IT professionals in Ukraine si...

Timeline

  1. 11.08.2026 21:36 2 articles · 13d ago

    Poisoned WireGuard-derived VPN client used to run commands on victim hosts

    Initial Disclosure

    Victims were steered from a failed WireGuard connection to a fake SopraVPN installer hosted on SourceForge. The altered client then decrypted embedded PowerShell and used WireGuard's execution path to run attacker commands.

    Show sources