Find notable cyber news and cases, enriched with sources, timelines, and signals.

Poisoned WireGuard-derived VPN client used to run commands on victim hosts

Malware Activity
First reported
Last updated
Happening score
H score 20
1 unique sources, 1 articles

Summary

Hide ▲

A poisoned WireGuard-derived VPN client now enables arbitrary command execution and payload downloads on victim hosts, expanding a recruiter-lure operation into direct malware delivery. The modified client is distributed as SopraVPN through fake SourceForge projects and a bogus website. Its configuration handling adds a non-standard SymmetricKey option that decrypts embedded PowerShell before execution. The Windows build can create a scheduled task, while the Linux build uses cURL to fetch a secondary executable.

Related Happenings

Sandworm fake recruiter campaign targeting Ukrainian IT workers

Campaign
H score32 First: 11.08.2026 21:36 Last: 11.08.2026 21:36 Sources 1

How related: "Specifically, on job search websites, after reviewing a candidate's resume, the attackers contact a potential victim – typically a system administrator or IT specialist – on behalf of an IT company (such as ATLAS Business Group),"

About this happening: An ongoing UAC-0145 / Sandworm campaign is using fake recruiter outreach on job sites, Telegram, and Zoom to target IT workers in Ukraine and push a poison...

Timeline

  1. 11.08.2026 21:36 2 articles · 2h ago

    Poisoned WireGuard-derived VPN client used to run commands on victim hosts

    Initial Disclosure

    Victims were steered from a failed WireGuard connection to a fake SopraVPN installer hosted on SourceForge. The altered client then decrypted embedded PowerShell and used WireGuard's execution path to run attacker commands.

    Show sources