Sandworm’s UAC-0145 Targets Ukrainian IT Workers with Fake Job Interviews

The Computer Emergency Response Team of Ukraine (CERT-UA) has uncovered a sophisticated social engineering campaign targeting Ukrainian IT professionals. This operation, attributed to the Russian state-sponsored group UAC-0145—a subgroup within the notorious Sandworm hacking unit—has been active since May 2026.

The attackers initiate contact by posing as recruiters on job search platforms, reaching out to system administrators and IT specialists. After reviewing a candidate’s resume, they engage the individual through the platform’s chat feature before transitioning the conversation to messaging applications like Telegram. Here, a supposed HR manager from a legitimate company, such as ATLAS Business Group, conducts a preliminary interview, discussing general work-related topics and assessing the candidate’s English proficiency.

Following this initial interaction, the candidate is invited to a Zoom video conference for a more in-depth interview. During this session, an English-speaking individual, appearing to be between 30 and 35 years old, conducts the interview. It remains uncertain whether this person is real or a synthetic persona generated using artificial intelligence.

Subsequently, the candidate receives an email containing instructions for a technical assessment. This includes configuration files for connecting to the company’s VPN using WireGuard and a link to a second Zoom meeting for test monitoring. However, upon attempting to connect to the VPN, the candidate encounters error messages. The attackers then suggest downloading a custom VPN client named SopraVPN, hosted on SourceForge, with links designed to mimic legitimate company websites.

Analysis reveals that this malicious VPN client is a modified version of WireGuard. The attackers have added a non-standard ‘SymmetricKey’ option to the configuration processing mechanism. This option contains BASE64-encoded data for AES-256-GCM encryption, allowing the execution of arbitrary PowerShell commands on the victim’s machine without their knowledge. Additionally, the Windows version of the VPN client creates a scheduled task to download a secondary payload from a remote server, while the Linux variant uses cURL to achieve the same objective.

This campaign underscores the evolving tactics of threat actors like UAC-0145, who are leveraging social engineering to infiltrate systems. By masquerading as legitimate recruiters and exploiting the trust inherent in job-seeking processes, they can deploy sophisticated malware that grants them control over targeted devices. This development highlights the critical need for heightened vigilance among job seekers and the importance of verifying the authenticity of recruitment communications.