Sandworm fake recruiter campaign targeting Ukrainian IT workers
Campaign
Summary
Hide ▲
Show ▼
CERT-UA says UAC-0145, a cluster linked to Sandworm (APT44), has run a fake recruiter campaign against system administrators and IT professionals in Ukraine since at least May 2026. The operation moves targets from job sites to Telegram and Zoom interviews, then pushes a poisoned WireGuard-based client and SourceForge lures tied to SopraVPN and Sopra Steria lookalikes. The malicious client can decrypt and run embedded PowerShell on Windows and fetch another executable through the VPN on Linux, creating a path to malware installation and unauthorized access.
Related Happenings
Poisoned WireGuard-derived VPN client used to run commands on victim hosts
Malware Activity
H score20
First: 11.08.2026 21:36
Last: 11.08.2026 21:36
Sources 1
How related:
"The essence of this trick is that the attackers' VPN client was compiled from the WireGuard source code with a number of modifications," CERT-UA explained.
About this happening:
A poisoned WireGuard-derived VPN client now enables arbitrary command execution and payload downloads on victim hosts, expanding a recruiter-lure operation into direct mal...
Poisoned WireGuard-derived VPN client used to run commands on victim hosts
Malware ActivityHow related: "The essence of this trick is that the attackers' VPN client was compiled from the WireGuard source code with a number of modifications," CERT-UA explained.
About this happening: A poisoned WireGuard-derived VPN client now enables arbitrary command execution and payload downloads on victim hosts, expanding a recruiter-lure operation into direct mal...
Roblox fake Xeno Executor installer campaign
Campaign
H score36
First: 03.08.2026 22:25
Last: 03.08.2026 22:25
Sources 1
About this happening:
The fake Xeno Executor installer campaign is an active Roblox-themed malware operation that uses gaming forums and Discord communities to lure victims into running...
Roblox fake Xeno Executor installer campaign
CampaignAbout this happening: The fake Xeno Executor installer campaign is an active Roblox-themed malware operation that uses gaming forums and Discord communities to lure victims into running...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
Campaign
H score39
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
CampaignAbout this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy
Malware Activity
H score41
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...
GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy
Malware ActivityAbout this happening: GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...
JINX-0164 cryptocurrency recruitment-lure campaign
Campaign
H score39
First: 28.05.2026 10:54
Last: 28.05.2026 10:54
Sources 1
About this happening:
A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...
JINX-0164 cryptocurrency recruitment-lure campaign
CampaignAbout this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...
Timeline
-
11.08.2026 21:36 3 articles · 13d ago
CERT-UA discloses Sandworm fake recruiter campaign targeting Ukrainian IT workers
Initial DisclosureCERT-UA disclosed a Russian state-linked social engineering campaign attributed to UAC-0145 within Sandworm and aimed at IT workers in Ukraine. The operation used fake recruiter outreach on job search sites, moved conversations to Telegram, invited victims to Zoom interviews, and pushed a poisoned WireGuard-based VPN and SourceForge-hosted lures designed to install malware and enable arbitrary command execution on the victim host. The campaign was assessed to have been ongoing since May 2026.
Show sources
- Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands — thehackernews.com — 11.08.2026 21:36
- Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands — thehackernews.com — 11.08.2026 21:36
- Sandworm hackers target IT pros with trojanized WireGuard VPN client — www.bleepingcomputer.com — 12.08.2026 00:07