Sandworm hackers target IT pros with trojanized WireGuard VPN client

Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May.

A report from the Ukrainian Computer Emergency Response Team (CERT) details a social engineering campaign attributed to UAC-0145, which is believed to be a sub-cluster of Sandworm (APT44). In the campaign, the threat actor targets victims while posing as IT companies and recruiters.

The agency says that the attacker studies the targets’ resumes uploaded on job sites and then initiates direct contact.

Conversations are then moved to Telegram to arrange a video interview over Zoom. During the interview, which is conducted in English, the candidates receive mock technical assignments that require them to connect to a corporate VPN.

In one case that CERT-UA observed, the attacker impersonated the international IT firm Sopra Steria using seemingly legitimate email addresses similar to the company’s office in Bulgaria.

“In parallel, additional instructions for the technical interview are sent via email, including configuration files for connecting to a ‘corporate’ VPN using Wireguard (Linux/Windows) to supposedly perform test tasks,” CERT-UA says.

The downloaded file is configured to produce a fake error. The attackers then prompt the victim to download a modified WireGuard-based client called “SopraVPN” from SourceForge.

The SourceForge page even includes a link to soprasteria-bg[.]com to increase credibility, although the domain has no connection to the legitimate company.

The trojanized client supports a malicious, nonstandard “SymmetricKey” configuration option that decrypts and executes embedded PowerShell code.

On Windows, the malicious command creates a scheduled task and downloads an additional payload from the Internet.

On Linux, it uses cURL to retrieve another executable from attacker-controlled infrastructure through the VPN.

CERT-UA also noted that WireGuard’s standard Base64 decoding was replaced in the trojanized version with a custom, dynamically generated Base64 alphabet, which renders key strings unreadable with standard decoders and protects the PowerShell code from analysis.

The Ukrainian cyber agency advises telecommunications providers and IT companies whose staff are targeted by this campaign to restrict corporate resource access to managed, continuously monitored devices protected by EDR, including when employees use personal equipment.

APT44 is notorious for targeting critical infrastructure and government entities both in Ukraine, and also in other countries.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Enhance privacy on up to 10 devices with this 5-year AdGuard VPN deal

This 3-year Surfshark VPN deal covers unlimited devices for $84

A year of Surfshark One+ & Incogni is $95 for a limited time

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

AdGuard’s popular VPN is only $35 for a 5-year subscription

LexisNexis shuts down services after suspicious activity on servers

Valve notifies Steam hardware customers of a data breach

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Webinar: Shadow AI in 2026 (and how attackers are taking advantage)

See how Skyhigh Security’s patent-pending approach secures every browser session without costly and clunky enterprise browser replacements.

Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.

See how real inboxes, fake stores and AI scams shaped H1 2026 cyber threats

Overdue a password health-check? Audit your Active Directory for free

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.