Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
- ID
- 13269
- Status
- summarized
- Published
- 12 Aug 2026, 2:36 AM
- Fetched
- 12 Aug 2026, 4:55 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/sandworm-linked-uac-0145-uses-fake-job.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 12 Aug 2026, 5:01 AM
- Tags
- Audience
- developersvibe_coders
What happened
CERT-UA reports that Russian GRU-linked Sandworm subgroup UAC-0145 has been running a fake recruitment campaign since May 2026, targeting Ukrainian IT workers and sysadmins via job sites and Telegram. The attackers impersonate recruiters from legitimate firms like Sopra Steria Bulgaria, conduct real Zoom interviews (possibly with an AI-generated persona), and trick victims into installing a malicious VPN client called 'SopraVPN' hosted on SourceForge after legitimate WireGuard configs fail.
Why it matters
If you or your team participate in remote job interviews or technical assessments requiring VPN installations from third parties, treat any 'custom VPN client' download link as suspicious—especially when a recruiter pivots from standard tools to a SourceForge-hosted binary after a config error. The possible use of AI-generated video personas in live interviews means you can no longer assume a real person on camera validates trust.
Discussion angle
How the bar for verifying identity in remote hiring has shifted now that nation-state actors may be deploying AI-generated video personas in live interviews—and what verification steps actually help versus security theater.