Hackers linked to Sandworm, also tracked as APT44 and UAC-0145, are luring system administrators and IT professionals with fake job offers to deliver malicious WireGuard-based tooling. The campaign uses recruiter impersonation, Telegram, Zoom interviews, and trojanized VPN software to run PowerShell payloads and steal access. #Sandworm #APT44 #UAC-0145 #WireGuard #SopraSteria #SourceForge
Keypoints
- UAC-0145, linked to Sandworm, is running a fake job offer campaign.
- Attackers study resumes and contact victims directly on job sites.
- Conversations are moved to Telegram and Zoom for fake technical interviews.
- Victims are tricked into installing a trojanized WireGuard client called SopraVPN.
- CERT-UA advises restricting access to managed devices with EDR protection.