Skip to content
Tech News
← Back to articles

Sandworm hackers target IT pros with trojanized WireGuard VPN client

read original more articles
Why This Matters

Sandworm hackers are targeting IT professionals with sophisticated social engineering campaigns, including fake job offers and trojanized VPN clients, to infiltrate organizations. This highlights the growing threat of state-sponsored cyber espionage and the importance of vigilance in cybersecurity practices. Consumers and businesses alike must stay alert to such tactics to protect sensitive data and infrastructure.

Key Takeaways

Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May.

A report from the Ukrainian Computer Emergency Response Team (CERT) details a social engineering campaign attributed to UAC-0145, which is believed to be a sub-cluster of Sandworm (APT44). In the campaign, the threat actor targets victims while posing as IT companies and recruiters.

The agency says that the attacker studies the targets' resumes uploaded on job sites and then initiates direct contact.

Conversations are then moved to Telegram to arrange a video interview over Zoom. During the interview, which is conducted in English, the candidates receive mock technical assignments that require them to connect to a corporate VPN.

Conversations with a supposed recruiter

Source: CERT-UA

In one case that CERT-UA observed, the attacker impersonated the international IT firm Sopra Steria using seemingly legitimate email addresses similar to the company’s office in Bulgaria.

“In parallel, additional instructions for the technical interview are sent via email, including configuration files for connecting to a 'corporate' VPN using Wireguard (Linux/Windows) to supposedly perform test tasks,” CERT-UA says.

Malicious emails and VPN download link

Source: CERT-UA

... continue reading