Sandworm Lures Ukrainian Admins Through Fake Hiring

CERT-UA says Sandworm subgroup UAC-0145 has run a hiring-themed campaign since May 2026, posing as recruiters to target Ukrainian system administrators and other IT specialists with fake job interviews. The bait moves from job-site chat to Telegram, then to Zoom and email, before the victim is told to install a VPN client for the technical test. The setup matters because the malicious VPN is presented as part of the interview process, so the target may run it with the same trust they would give normal corporate software. CERT-UA says that client can execute commands on the machine, which means the first foothold may land on a privileged IT workstation rather than an ordinary user laptop. If your organization puts sysadmins, security engineers, or technical recruiters in the hiring pipeline, this is the sort of pretext that can turn a single workstation compromise into broader internal or supplier-facing access.

Part of the PlainSec briefing for 2026-08-11

Editions

Sources