Poisoned WireGuard-derived VPN client used to run commands on victim hosts
Malware Activity
Summary
Hide ▲
Show ▼
A poisoned WireGuard-derived VPN client now enables arbitrary command execution and payload downloads on victim hosts, expanding a recruiter-lure operation into direct malware delivery. The modified client is distributed as SopraVPN through fake SourceForge projects and a bogus website. Its configuration handling adds a non-standard SymmetricKey option that decrypts embedded PowerShell before execution. The Windows build can create a scheduled task, while the Linux build uses cURL to fetch a secondary executable.
Related Happenings
Sandworm fake recruiter campaign targeting Ukrainian IT workers
Campaign
H score32
First: 11.08.2026 21:36
Last: 11.08.2026 21:36
Sources 1
How related:
"Specifically, on job search websites, after reviewing a candidate's resume, the attackers contact a potential victim – typically a system administrator or IT specialist – on behalf of an IT company (such as ATLAS Business Group),"
About this happening:
An ongoing UAC-0145 / Sandworm campaign is using fake recruiter outreach on job sites, Telegram, and Zoom to target IT workers in Ukraine and push a poison...
Sandworm fake recruiter campaign targeting Ukrainian IT workers
CampaignHow related: "Specifically, on job search websites, after reviewing a candidate's resume, the attackers contact a potential victim – typically a system administrator or IT specialist – on behalf of an IT company (such as ATLAS Business Group),"
About this happening: An ongoing UAC-0145 / Sandworm campaign is using fake recruiter outreach on job sites, Telegram, and Zoom to target IT workers in Ukraine and push a poison...
Timeline
-
11.08.2026 21:36 2 articles · 2h ago
Poisoned WireGuard-derived VPN client used to run commands on victim hosts
Initial DisclosureVictims were steered from a failed WireGuard connection to a fake SopraVPN installer hosted on SourceForge. The altered client then decrypted embedded PowerShell and used WireGuard's execution path to run attacker commands.
Show sources
- Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands — thehackernews.com — 11.08.2026 21:36
- Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands — thehackernews.com — 11.08.2026 21:36