Russian Sandworm Hackers Weaponize WireGuard VPN in Fake Job Scams
Russian state-linked hacking group Sandworm launches an elaborate social engineering campaign targeting IT professionals and system administrators through fake job offers. According to Ukraine's Computer Emergency Response Team (CERT-UA), the operation runs under the sub-cluster UAC-0145, with attackers impersonating legitimate IT companies and recruiters. The hackers study their targets' resumes from job sites, then initiate contact and move conversations to Telegram before scheduling fake video interviews on Zoom.
During the interview process, candidates receive mock technical assignments requiring them to connect to a corporate VPN. In one observed case, attackers impersonate the international firm Sopra Steria, directing victims to download a trojanized WireGuard-based client called SopraVPN from SourceForge. The malicious app appears convincing, complete with a fake company domain and realistic configuration files. Once installed, the client triggers a fake error message while secretly executing embedded PowerShell code that creates scheduled tasks and downloads additional malicious payloads.
The trojanized VPN client employs custom modifications to evade detection, including a dynamically generated Base64 alphabet that prevents standard decoders from analyzing the malicious code. The malware successfully targets both Windows and Linux environments. CERT-UA advises telecommunications providers and IT companies to remain vigilant, as the campaign demonstrates increasingly sophisticated techniques designed specifically to compromise technical professionals with privileged system access.