Ethical Hacking News
A new wave of sophistication has been added to the threat landscape by the Sandworm-linked UAC-0145 campaign, which utilizes fake job interviews as a means of tricking IT workers into installing compromised VPN clients. To stay ahead of this evolving threat, it is essential for organizations and individuals to remain vigilant and take proactive measures to protect themselves against such threats.
The Sandworm (APT44) group has been using fake job interviews as a means of tricking IT workers into installing compromised VPN clients. The UAC-0145 campaign, attributed to the Ukrainian Computer Emergency Response Team (CERT-UA), has been ongoing since May 2026 with the goal of infecting IT workers' systems. Attackers pose as recruiters, contacting potential victims on job search websites and using messaging apps like Telegram to build trust. The campaign uses a combination of social engineering tactics, including Zoom videoconferences and emails, to trick victims into installing compromised VPN clients. The compromised VPN client has been crafted with modifications that allow attackers to run arbitrary commands on the victim's host without their knowledge.
The threat landscape has witnessed an influx of sophisticated social engineering campaigns orchestrated by various nation-state actors in recent times. One such campaign, linked to the notorious Sandworm (APT44) group, has garnered significant attention due to its cunning use of fake job interviews as a means of tricking IT workers into installing compromised VPN clients. In this article, we will delve into the details of this campaign, which is attributed to the UAC-0145 threat cluster.
According to the Computer Emergency Response Team of Ukraine (CERT-UA), the UAC-0145 campaign has been ongoing since May 2026, with the primary goal of infecting IT workers' systems. The attackers masquerade as recruiters, contacting potential victims on job search websites after reviewing their resumes. These initial communications take place via built-in online chat before shifting to messaging apps like Telegram, where a preliminary chat takes place with a purported HR manager.
The conversation during this stage involves general work-related questions and the candidates' English language proficiency, all designed to create a sense of legitimacy and build trust with the victim. Subsequently, an invitation is extended to join a Zoom videoconference call, which appears to be a legitimate opportunity for the candidate to discuss their qualifications. However, it is unclear whether the person participating in the interview is a genuine participant or a synthetic persona generated using artificial intelligence (AI).
Following the meeting, additional instructions are sent via email, including configuration files for connecting to the corporate VPN using WireGuard to supposedly complete an assessment. A link to a second Zoom meeting is also provided during which the test is monitored. However, if the victim attempts to connect to the VPN using the provided configuration files, they encounter error messages, prompting the threat actors to recommend downloading a custom VPN solution named SopraVPN hosted on SourceForge.
This compromised VPN client has been crafted from the WireGuard source code with various modifications, including support for the non-standard 'SymmetricKey' option. This mechanism allows an attacker to run arbitrary commands on the victim's host without their knowledge. Furthermore, the Windows VPN client utilizes a PowerShell command to create a scheduled task that downloads a secondary payload from a remote URL, while the Linux variant uses cURL to download the executable file from the attackers' infrastructure via a VPN.
The disclosure by CERT-UA serves as a stark reminder of the evolving sophistication and complexity of social engineering tactics employed by nation-state actors. It is essential for IT professionals to remain vigilant and take proactive measures to protect themselves against such threats, including allowing access to corporate resources only from managed devices with appropriate security software installed.
Organizations are recommended to ensure that relevant policies are configured and continuous monitoring is enforced to prevent potential malware attacks. The latest development also highlights the growing trend of fake recruitment campaigns employed by various adversarial actors, including Chinese, Iranian, North Korean, and Russian threat actors.
This campaign serves as a valuable lesson for organizations and individuals alike in the importance of staying vigilant against such sophisticated social engineering tactics and ensuring that their security measures are up-to-date. By understanding the intricacies of these campaigns, we can better equip ourselves to defend against them and mitigate the potential risks associated with compromised VPN clients.
Related Information:
https://www.ethicalhackingnews.com/articles/Sandworm-Linked-UAC-0145-A-Sophisticated-Social-Engineering-Campaign-Utilizing-Fake-Job-Interviews-to-Push-Compromised-VPN-Clients-ehn.shtml
https://thehackernews.com/2026/08/sandworm-linked-uac-0145-uses-fake-job.html
Published: Tue Aug 11 14:58:41 2026 by llama3.2 3B Q4_K_M