Find notable cyber news and cases, enriched with sources, timelines, and signals.

Sandworm fake recruiter campaign targeting Ukrainian IT workers

Campaign
First reported
Last updated
Happening score
H score 32
2 unique sources, 2 articles

Summary

Hide ▲

CERT-UA says UAC-0145, a cluster linked to Sandworm (APT44), has run a fake recruiter campaign against system administrators and IT professionals in Ukraine since at least May 2026. The operation moves targets from job sites to Telegram and Zoom interviews, then pushes a poisoned WireGuard-based client and SourceForge lures tied to SopraVPN and Sopra Steria lookalikes. The malicious client can decrypt and run embedded PowerShell on Windows and fetch another executable through the VPN on Linux, creating a path to malware installation and unauthorized access.

Related Happenings

Poisoned WireGuard-derived VPN client used to run commands on victim hosts

Malware Activity
H score20 First: 11.08.2026 21:36 Last: 11.08.2026 21:36 Sources 1

How related: "The essence of this trick is that the attackers' VPN client was compiled from the WireGuard source code with a number of modifications," CERT-UA explained.

About this happening: A poisoned WireGuard-derived VPN client now enables arbitrary command execution and payload downloads on victim hosts, expanding a recruiter-lure operation into direct mal...

Roblox fake Xeno Executor installer campaign

Campaign
H score36 First: 03.08.2026 22:25 Last: 03.08.2026 22:25 Sources 1

About this happening: The fake Xeno Executor installer campaign is an active Roblox-themed malware operation that uses gaming forums and Discord communities to lure victims into running...

GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations

Campaign
H score39 First: 29.05.2026 01:24 Last: 29.05.2026 01:24 Sources 1

About this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...

GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy

Malware Activity
H score41 First: 29.05.2026 01:24 Last: 29.05.2026 01:24 Sources 1

About this happening: GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...

JINX-0164 cryptocurrency recruitment-lure campaign

Campaign
H score39 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...

Timeline

  1. 11.08.2026 21:36 3 articles · 13d ago

    CERT-UA discloses Sandworm fake recruiter campaign targeting Ukrainian IT workers

    Initial Disclosure

    CERT-UA disclosed a Russian state-linked social engineering campaign attributed to UAC-0145 within Sandworm and aimed at IT workers in Ukraine. The operation used fake recruiter outreach on job search sites, moved conversations to Telegram, invited victims to Zoom interviews, and pushed a poisoned WireGuard-based VPN and SourceForge-hosted lures designed to install malware and enable arbitrary command execution on the victim host. The campaign was assessed to have been ongoing since May 2026.

    Show sources