Threats · 48 days ago
CERT-UA says Sandworm subgroup UAC-0145 has run a hiring-themed campaign since May 2026, posing as recruiters to target Ukrainian system administrators and other IT specialists with fake job interviews. The bait moves from job-site chat to Telegram, then to Zoom and email, before the victim is told to install a VPN client for the technical test.
The setup matters because the malicious VPN is presented as part of the interview process, so the target may run it with the same trust they would give normal corporate software. CERT-UA says that client can execute commands on the machine, which means the first foothold may land on a privileged IT workstation rather than an ordinary user laptop.
If your organization puts sysadmins, security engineers, or technical recruiters in the hiring pipeline, this is the sort of pretext that can turn a single workstation compromise into broader internal or supplier-facing access.
2 sources covering this story
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands | Read more hacking news on The Hacker News cybersecurity news website and learn how to protect against cyberattacks and software vulnerabilities.
Sandworm hackers target IT pros with trojanized WireGuard VPN client
Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May.
Part of the PlainSec briefing for 2026-08-11