Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Sandworm has turned the routine job interview into a route for compromising IT workers.

The campaign uses convincing recruiter conversations, live video calls and a booby-trapped virtual private network client to reach people who may hold privileged access to company systems.

The operation targets system administrators and other IT specialists after attackers study their resumes on job-search sites.

It begins with a message from a supposed employer, moves into a chat and then presents a technical assessment that appears to need a corporate VPN connection.

CERT-UA analysts identified the activity as UAC-0145, a Sandworm-linked subcluster also known as APT44 and Seashell Blizzard.

The agency said the activity has continued since at least May 2026, showing how staged recruitment fraud can bypass technical suspicion.

CERT-UA said in a report shared with Cyber Security News (CSN) that the campaign matters because its targets maintain networks and remote access. A credible interview creates pressure to install unfamiliar software quickly.

Sandworm Fake Job Interviews

The attackers reportedly approach candidates while impersonating IT employers.

Early exchanges take place through a job-site chat and Telegram, followed by a basic English-language screening and a Zoom meeting that appears to involve a real person.

primary interaction (Source – Cert-UA)

This patient approach resembles fake job interview threats, where familiar hiring steps lower a candidate’s guard.

Candidates then receive technical-interview instructions by email, including WireGuard configuration files for Linux or Windows. The files are framed as a way to complete a test task on a corporate network.

When the connection predictably fails, the interviewer recommends a tailored VPN client called SopraVPN from a project page linked by the fake company site.

That detour is the central trap. The application is a modified build based on WireGuard source code.

Earlier reporting on poisoned VPN apps illustrates why a working client is not proof that a download is safe.

CERT-UA found that the altered client accepts an extra configuration setting, SymmetricKey. It uses information hidden there, together with the configuration’s private key, to decrypt embedded PowerShell code.

Communication with an ‘HR manager’ (Source – Cert-UA)

On Windows, that code creates a scheduled task and downloads an additional payload from the internet.

The Linux variant uses curl to retrieve another executable from attacker-controlled infrastructure through the VPN, whose configuration provides the DNS server address. The modified software also changes normal Base64 key decoding.

Recruitment Lures Turn Trust Into Access

The campaign is notable for the social engineering around it. A genuine-looking conversation and live video interview make the software request seem reasonable.

Similar recruiter impersonation attacks show how threat groups use employment processes to persuade technical people to run tools they would otherwise question.

For employers, the risk extends beyond one candidate. Administrators handle credentials, servers, VPNs and security controls. Control of such a device may let an attacker probe connected systems or steal data.

CERT-UA urged IT professionals to watch for these recruitment tactics and advised organizations, especially telecommunications providers and IT companies, to permit corporate-resource access only from managed devices.

Those devices should have endpoint protection, defined policies and continuous monitoring, even when personally owned.

Candidates can reduce exposure by independently verifying an employer through official contact channels before joining an interview or installing software. Treat a request to use a custom VPN, altered configuration or external download as a stop sign.

This is especially important when the request follows a claimed technical problem, a pattern also seen in malicious job-platform tactics.

Security teams should alert staff that legitimate recruiting does not require shortcuts around established software sources and device controls.

Interview tasks that require code or network access belong in isolated, disposable environments, not on an administrator’s primary workstation.

Review unusual scheduled tasks, PowerShell activity and new VPN configurations.

Teams should also establish a clear process for reporting suspicious recruitment contact, allowing security staff to verify the employer, preserve evidence and warn colleagues before one risky download spreads through an organization quickly.

Indicators of compromise (IoCs):-

Type Indicator Description
SHA-512 bf6670760305228fd83a5e1467a99d914646ea832a61c9f7bdb11fee64ad82ae6d9856d2f3a4b36a8a4a571145be1260 Hash associated with sopravpn_v7__1_.exe
File name sopravpn_v7__1_.exe Trojanized VPN client file
SHA-512 d478e96bfb0f3a586c6d17d8bfc874ea480ab92995295378c9b30b8b6fb61516313ed7482eb893967841b05e233fe341 Hash associated with sopraconf.conf
File name sopraconf.conf Malicious WireGuard configuration file
SHA-512 088acb50f7a7e54f887da7b561e1861322a21958a2c4752214192175793c13acae2f6d766007d55d2140f1570ae1df67 Hash associated with sopraconfLinux.conf
File name sopraconfLinux.conf Linux WireGuard configuration file
SHA-512 be11cc798c239b9d4eaa76ab03d07168aeb702f65445d12605a84be6fa31545c71be0bf619b1cbedbee5800a43fc6793 Hash associated with SopraVPN.exe
SHA-512 676f44c7fa03693247d0dd5c3a0e13f76a60152f7c83d3416925316b75eb7720953cdd69aae9f0e088c789c25f51437f Hash associated with SopraVPN.exe
File name SopraVPN.exe Trojanized VPN client
URL hXXps://douncloud[.]site/sitedatastorageadvanced/?subid=%UUID%---%MACHINEG Payload delivery URL
URL hXXps://sourceforge[.]net/projects/soprabulgariavpn/files/sopravpn_v10.exenload Malicious VPN download URL
URL hXXps://sourceforge[.]net/projects/sopravpn/files/sopravpn_v5.exe/download Malicious VPN download URL
URL https://sourceforge[.]net/projects/sopravpn/files/sopravpn.exe/download Malicious VPN download URL
URL hXXps://soprasteria-bg[.]com/ Fake company website
URL hXXps://atlasgroup-ua[.]com/ Impersonated organization website
Network endpoint udp://139.28.36[.]23:51820 VPN endpoint
IP address 139.28.36[.]23 Infrastructure IP address
Domain douncloud[.]site Payload-hosting domain
Domain atlasgroup-ua[.]com Impersonation domain
Domain soprasteria-bg[.]com Fake company domain
Domain soprasteriabg[.]com Related suspicious domain
Telegram account @Sales_ManagerABG Recruiter-themed Telegram account
Email address alex.boichenkoit@ukr[.]net Observed email address
Email address mike.weitzman@soprasteria-bg[.]com Spoofed recruiter email address
File path /usr/libexec/timesyncd-check Linux payload path
Command curl >/dev/null 2>&1 || apt install -y curl >/dev/null 2>&1; Command used to obtain curl before downloading payloads

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world