"Specifically, on job search websites, after reviewing a candidate's resume, the attackers contact a potential victim – typically a system administrator or IT specialist – on behalf of an IT company (such as ATLAS Business Group)," CERT‑UA said.
CERT‑UA attributes the campaign to UAC‑0145, a Sandworm subgroup
Ukraine's Computer Emergency Response Team (CERT‑UA) says it has tracked an ongoing social engineering campaign since May 2026 that targets IT workers in the country. The agency pinned the activity on a threat cluster it tracks as UAC‑0145, described as a subgroup within Sandworm (also named APT44, Seashell Blizzard, and UAC‑0002), "a sophisticated hacking group affiliated with the GRU." The disclosure follows a recent attribution by the same agency tying the actor to an earlier ClickFix social‑engineering campaign that delivered data‑stealing malware.
Staged interviews via job sites, Telegram and Zoom
CERT‑UA lays out a consistent lure: attackers review resumes on job search websites, then pose as recruiters for legitimate firms. Initial contact uses built‑in chat functionality on those sites, then shifts to messaging apps such as Telegram for preliminary screening. The purported HR contact claims to be screening candidates for Sopra Steria Bulgaria and asks routine work and English‑language questions before inviting the target to a Zoom technical interview.
The Zoom call itself is described by CERT‑UA as taking place with "an English‑speaking man who appears to be between 30 and 35 years old." The advisory explicitly notes it is unclear whether that person was a real interviewer or a synthetic persona produced using artificial intelligence.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageBogus VPN files, SourceForge links, and the SopraVPN lure
As part of the interview process, candidates receive an email with configuration files intended to connect them to a corporate VPN using WireGuard so they can complete a remote assessment. When those configurations produce connection errors, the operators recommend downloading a custom client they call "SopraVPN," hosted on SourceForge and distributed with links designed to mimic Sopra Steria Bulgaria's web address ("soprasteria‑bg[.]com"). CERT‑UA quotes two SourceForge project paths used by the attackers:
- sourceforge[.]net/projects/soprabulgariavpn
- sourceforge[.]net/projects/sopravpn
The Hacker News identified a third SourceForge project, "sourceforge[.]net/projects/soprasteriavpn/," with cached marketing copy describing it as "an open‑source corporate VPN solution designed for businesses seeking secure remote access and site‑to‑site connectivity without expensive licensing fees." CERT‑UA says none of these projects are available for download.
Modified WireGuard client lets attackers run commands
CERT‑UA's technical analysis describes a poisoned WireGuard client compiled from WireGuard source code with deliberate modifications. The modified client accepts a non‑standard "SymmetricKey" option; its value is a BASE64 string that encodes an AES‑256‑GCM blob containing a nonce, ciphertext, and authentication tag. The advisory states: "A 32‑byte value obtained by decoding 'PrivateKey' is used as the AES‑256 key. The PowerShell code decrypted in this way is then passed to the standard 'runScriptCommand' mechanism, which WireGuard uses, in particular, to execute commands specified by the 'PostUp' option."
Put plainly, CERT‑UA concludes the tampered WireGuard build provides the attackers a mechanism to execute arbitrary commands on a victim host without their knowledge.
Windows scheduled tasks, Linux cURL fetches, and the unknown secondary payload
The agency details platform differences for next‑stage delivery. The Windows VPN client uses a PowerShell command to create a scheduled task that downloads a secondary payload from a remote URL. The Linux variant employs cURL over the VPN to fetch an executable from the attackers' infrastructure. CERT‑UA does not disclose the exact nature of the secondary payload.
What this means for IT professionals, Sopra Steria Bulgaria, and SourceForge
- IT professionals and security teams: CERT‑UA urges vigilance for recruitment‑style social engineering and recommends allowing corporate resource access only from managed devices with appropriate security software, correctly configured policies, and continuous monitoring.
- Sopra Steria Bulgaria (and other named employers): the company name is being impersonated as part of the lure; organizations whose brands are referenced should be prepared to support targeted employees and coordinate with incident responders when fraudulent recruitment approaches are reported.
- Open‑source hosts like SourceForge: the campaign used SourceForge project pages to host or masquerade a malicious client; hosting platforms and downstream users should note CERT‑UA's observation that the projects referenced were not available for download and that adversaries may attempt to weaponize or mimic well‑known distribution channels.
The disclosure also places this campaign in a growing pattern: CERT‑UA notes that Russian threat actors have joined Chinese, Iranian, and North Korean adversaries in using fake recruitment campaigns to gain unauthorized access to targeted systems. For now, the immediate technical danger is clear — a tampered VPN client that subverts legitimate configuration options to run code — and the practical defense the agency recommends is straightforward: limit corporate access to managed, monitored endpoints and watch for recruitment approaches that request installation of unofficial tooling.
Original reporting: https://thehackernews.com/2026/08/sandworm-linked-uac-0145-uses-fake-job.html




