"In parallel, additional instructions for the technical interview are sent via email, including configuration files for connecting to a 'corporate' VPN using Wireguard (Linux/Windows) to supposedly perform test tasks," CERT-UA says.
UAC-0145's fake job-interview social engineering
The Ukrainian Computer Emergency Response Team (CERT-UA) says a campaign attributed to UAC-0145 — believed to be a sub-cluster of the Russian-linked Sandworm group (APT44) — has been targeting system administrators and IT professionals through bogus job offers since at least May. According to CERT-UA, the attackers study resumes posted to job sites, make direct contact while posing as recruiters or IT firms, move conversations to Telegram, and schedule video interviews over Zoom conducted in English.
Trojanized WireGuard client "SopraVPN" on SourceForge
CERT-UA observed one instance in which the actor impersonated the international IT firm Sopra Steria using email addresses similar to the company’s office in Bulgaria. Interview materials sent to candidates included configuration files for a supposed corporate VPN and a prompt to download a modified WireGuard-based client named "SopraVPN" hosted on SourceForge. The SourceForge page even linked to soprasteria-bg[.]com to increase credibility; CERT-UA says that domain has no connection to the legitimate company.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTechnical tricks: SymmetricKey, custom Base64, and embedded PowerShell
The trojanized client implements a nonstandard configuration option labelled "SymmetricKey." CERT-UA reports that this option decrypts and executes embedded PowerShell code. In addition, the trojanized WireGuard replaces the standard Base64 decoding routine with a custom, dynamically generated Base64 alphabet. That change renders key strings unreadable by standard decoders and, according to CERT-UA, protects the embedded PowerShell from straightforward analysis.
Observed behavior on Windows and Linux
CERT-UA details platform-specific post-install actions. On Windows, the malicious client creates a scheduled task and downloads an additional payload from the Internet. On Linux, the client uses cURL to retrieve another executable from attacker-controlled infrastructure over the VPN connection. In all cases, the initial download is configured to produce a fake error that prompts the victim to fetch the trojanized client.
What this means for telecommunications providers, IT companies, and IT professionals
- Telecommunications providers and IT companies: CERT-UA advises restricting corporate resource access to managed, continuously monitored devices protected by endpoint detection and response (EDR), including when employees use personal equipment.
- IT professionals and system administrators (the targeted group): the campaign specifically leverages recruitment channels — resumes on job sites, Telegram, and Zoom interviews — to entice technical tasks that require VPN connections, turning a routine vetting step into an initial access vector.
- Recruiters and hiring teams used as the impersonated identity (e.g., Sopra Steria in the observed case): the campaign shows how attackers mimic legitimate corporate contact points and domain references (soprasteria-bg[.]com) to build credibility.
Context: credential access, APT44 targeting, and the Blue Report 2026
CERT-UA notes that APT44 has a history of targeting critical infrastructure and government entities in Ukraine and in other countries. The advisory underscores a broader operational risk: "Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply." The Blue Report 2026, cited in the source material, measures defenses technique by technique across 338 million simulations run in customer production environments — a reminder, in CERT-UA's framing, that initial prevention does not by itself eliminate post-compromise risk.
Sandworm-aligned attackers are combining familiar elements — job postings, chat apps, video interviews, and trusted open-source distribution channels — with bespoke malware changes that frustrate standard analysis. For organizations whose staff are likely to be contacted through recruitment channels, CERT-UA’s specific guidance is direct: limit access to managed, monitored endpoints with EDR even when tasks require employees to use personal equipment. The remaining question the campaign poses is straightforward and urgent: will target organizations treat job-interview VPNs as an authentication boundary or as a potential infection vector?




