cognitive cybersecurity intelligence

News and Analysis

Search

Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals

Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals

Sandworm has turned the routine job interview into a route for compromising IT workers.

The campaign uses convincing recruiter conversations, live video calls and a booby-trapped virtual private network client to reach people who may hold privileged access to company systems.

The operation targets system administrators and other IT specialists after attackers study their resumes on job-search sites.

It begins with a message from a supposed employer, moves into a chat and then presents a technical assessment that appears to need a corporate VPN connection.

CERT-UA analysts identified the activity as UAC-0145, a Sandworm-linked subcluster also known as APT44 and Seashell Blizzard.

The agency said the activity has continued since at least May 2026, showing how staged recruitment fraud can bypass technical suspicion.

CERT-UA said in a report shared with Cyber Security News (CSN) that the campaign matters because its targets maintain networks and remote access. A credible interview creates pressure to install unfamiliar software quickly.

Sandworm Fake Job Interviews

The attackers reportedly approach candidates while impersonating IT employers.

Early exchanges take place through a job-site chat and Telegram, followed by a basic English-language screening and a Zoom meeting that appears to involve a real person.

primary interaction (Source – Cert-UA)

This patient approach resembles fake job interview threats, where familiar hiring steps lower a candidate’s guard.

Candidates then receive technical-interview instructions by email, including WireGuard configuration files for Linux or Windows. The files are framed as a way to complete a test task on a corporate network.

When the connection predictably fails, the interviewer recommends a tailored VPN client called SopraVPN from a project page linked by the fake company site.

That detour is the central trap. The application is a modified build based on WireGuard source code.

Earlier reporting on poisoned VPN apps illustrates why a working client is not proof that a download is safe.

CERT-UA found that the altered client accepts an extra configuration setting, SymmetricKey. It uses information hidden there, together with the configuration’s private key, to decrypt embedded PowerShell code.

Communication with an ‘HR manager’ (Source – Cert-UA)

On Windows, that code creates a scheduled task and downloads an additional payload from the internet.

The Linux variant uses curl to retrieve another executable from attacker-controlled infrastructure through the VPN, whose configuration provides the DNS server address. The modified software also changes normal Base64 key decoding.

Recruitment Lures Turn Trust Into Access

The campaign is notable for the social engineering around it. A genuine-looking conversation and live video interview make the software request seem reasonable.

Similar recruiter impersonation attacks show how threat groups use employment processes to persuade technical people to run tools they would otherwise question.

For employers, the risk extends beyond one candidate. Administrators handle credentials, servers, VPNs and security controls. Control of such a device may let an attacker probe connected systems or steal data.

CERT-UA urged IT professionals to watch for these recruitment tactics and advised organizations, especially telecommunications providers and IT companies, to permit corporate-resource access only from managed devices.

Those devices should have endpoint protection, defined policies and continuous monitoring, even when personally owned.

Candidates can reduce exposure by independently verifying an employer through official contact channels before joining an interview or installing software. Treat a request to use a custom VPN, altered configuration or external download as a stop sign.

This is especially important when the request follows a claimed technical problem, a pattern also seen in malicious job-platform tactics.

Security teams should alert staff that legitimate recruiting does not require shortcuts around established software sources and device controls.

Interview tasks that require code or network access belong in isolated, disposable environments, not on an administrator’s primary workstation.

Review unusual scheduled tasks, PowerShell activity and new VPN configurations.

Teams should also establish a clear process for reporting suspicious recruitment contact, allowing security staff to verify the employer, preserve evidence and warn colleagues before one risky download spreads through an organization quickly.

Indicators of compromise (IoCs):-

TypeIndicatorDescriptionSHA-512bf6670760305228fd83a5e1467a99d914646ea832a61c9f7bdb11fee64ad82ae6d9856d2f3a4b36a8a4a571145be1260Hash associated with sopravpn_v7__1_.exeFile namesopravpn_v7__1_.exeTrojanized VPN client fileSHA-512d478e96bfb0f3a586c6d17d8bfc874ea480ab92995295378c9b30b8b6fb61516313ed7482eb893967841b05e233fe341Hash associated with sopraconf.confFile namesopraconf.confMalicious WireGuard configuration fileSHA-512088acb50f7a7e54f887da7b561e1861322a21958a2c4752214192175793c13acae2f6d766007d55d2140f1570ae1df67Hash associated with sopraconfLinux.confFile namesopraconfLinux.confLinux WireGuard configuration fileSHA-512be11cc798c239b9d4eaa76ab03d07168aeb702f65445d12605a84be6fa31545c71be0bf619b1cbedbee5800a43fc6793Hash associated with SopraVPN.exeSHA-512676f44c7fa03693247d0dd5c3a0e13f76a60152f7c83d3416925316b75eb7720953cdd69aae9f0e088c789c25f51437fHash associated with SopraVPN.exeFile nameSopraVPN.exeTrojanized VPN clientURLhXXps://douncloud[.]site/sitedatastorageadvanced/?subid=%UUID%—%MACHINEGPayload delivery URLURLhXXps://sourceforge[.]net/projects/soprabulgariavpn/files/sopravpn_v10.exenloadMalicious VPN download URLURLhXXps://sourceforge[.]net/projects/sopravpn/files/sopravpn_v5.exe/downloadMalicious VPN download URLURLhttps://sourceforge[.]net/projects/sopravpn/files/sopravpn.exe/downloadMalicious VPN download URLURLhXXps://soprasteria-bg[.]com/Fake company websiteURLhXXps://atlasgroup-ua[.]com/Impersonated organization websiteNetwork endpointudp://139.28.36[.]23:51820VPN endpointIP address139.28.36[.]23Infrastructure IP addressDomaindouncloud[.]sitePayload-hosting domainDomainatlasgroup-ua[.]comImpersonation domainDomainsoprasteria-bg[.]comFake company domainDomainsoprasteriabg[.]comRelated suspicious domainTelegram account@Sales_ManagerABGRecruiter-themed Telegram accountEmail addressalex.boichenkoit@ukr[.]netObserved email addressEmail addressmike.weitzman@soprasteria-bg[.]comSpoofed recruiter email addressFile path/usr/libexec/timesyncd-checkLinux payload pathCommandcurl >/dev/null 2>&1 \|\| apt install -y curl >/dev/null 2>&1;Command used to obtain curl before downloading payloads

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
The post Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts