Find notable cyber news and cases, enriched with sources, timelines, and signals.

Sandworm fake recruiter campaign targeting Ukrainian IT workers

Campaign
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

An ongoing UAC-0145 / Sandworm campaign is using fake recruiter outreach on job sites, Telegram, and Zoom to target IT workers in Ukraine and push a poisoned WireGuard-based VPN. The operation has been active since May 2026 and is designed to trick victims into installing malware during a staged technical interview. The end result is a path to unauthorized access and remote command execution on victim systems.

Related Happenings

Poisoned WireGuard-derived VPN client used to run commands on victim hosts

Malware Activity
H score20 First: 11.08.2026 21:36 Last: 11.08.2026 21:36 Sources 1

How related: "The essence of this trick is that the attackers' VPN client was compiled from the WireGuard source code with a number of modifications," CERT-UA explained.

About this happening: A poisoned WireGuard-derived VPN client now enables arbitrary command execution and payload downloads on victim hosts, expanding a recruiter-lure operation into direct mal...

Roblox fake Xeno Executor installer campaign

Campaign
H score36 First: 03.08.2026 22:25 Last: 03.08.2026 22:25 Sources 1

About this happening: The fake Xeno Executor installer campaign is an active Roblox-themed malware operation that uses gaming forums and Discord communities to lure victims into running...

GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations

Campaign
H score39 First: 29.05.2026 01:24 Last: 29.05.2026 01:24 Sources 1

About this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...

Fake Gemini CLI and Claude Code SEO-poisoning infostealer campaign

Campaign
H score33 First: 22.05.2026 14:30 Last: 22.05.2026 14:30 Sources 1

About this happening: Cyber threat actors ran a malicious SEO-poisoning campaign that impersonated Google Gemini CLI and Anthropic Claude Code to push malicious downloads. The operation...

HeartlessSoul phishing and malvertising espionage campaign targeting aerospace firms and drone operators

Campaign
H score29 First: 11.05.2026 15:00 Last: 11.05.2026 15:00 Sources 1

About this happening: The HeartlessSoul operation is using phishing and malvertising to target aerospace firms and drone operators, raising the risk of geospatial data theft from co...

Timeline

  1. 11.08.2026 21:36 2 articles · 2h ago

    CERT-UA discloses Sandworm fake recruiter campaign targeting Ukrainian IT workers

    Initial Disclosure

    CERT-UA disclosed a Russian state-linked social engineering campaign attributed to UAC-0145 within Sandworm and aimed at IT workers in Ukraine. The operation used fake recruiter outreach on job search sites, moved conversations to Telegram, invited victims to Zoom interviews, and pushed a poisoned WireGuard-based VPN and SourceForge-hosted lures designed to install malware and enable arbitrary command execution on the victim host. The campaign was assessed to have been ongoing since May 2026.

    Show sources