Sandworm fake recruiter campaign targeting Ukrainian IT workers
Campaign
Summary
Hide ▲
Show ▼
An ongoing UAC-0145 / Sandworm campaign is using fake recruiter outreach on job sites, Telegram, and Zoom to target IT workers in Ukraine and push a poisoned WireGuard-based VPN. The operation has been active since May 2026 and is designed to trick victims into installing malware during a staged technical interview. The end result is a path to unauthorized access and remote command execution on victim systems.
Related Happenings
Poisoned WireGuard-derived VPN client used to run commands on victim hosts
Malware Activity
H score20
First: 11.08.2026 21:36
Last: 11.08.2026 21:36
Sources 1
How related:
"The essence of this trick is that the attackers' VPN client was compiled from the WireGuard source code with a number of modifications," CERT-UA explained.
About this happening:
A poisoned WireGuard-derived VPN client now enables arbitrary command execution and payload downloads on victim hosts, expanding a recruiter-lure operation into direct mal...
Poisoned WireGuard-derived VPN client used to run commands on victim hosts
Malware ActivityHow related: "The essence of this trick is that the attackers' VPN client was compiled from the WireGuard source code with a number of modifications," CERT-UA explained.
About this happening: A poisoned WireGuard-derived VPN client now enables arbitrary command execution and payload downloads on victim hosts, expanding a recruiter-lure operation into direct mal...
Roblox fake Xeno Executor installer campaign
Campaign
H score36
First: 03.08.2026 22:25
Last: 03.08.2026 22:25
Sources 1
About this happening:
The fake Xeno Executor installer campaign is an active Roblox-themed malware operation that uses gaming forums and Discord communities to lure victims into running...
Roblox fake Xeno Executor installer campaign
CampaignAbout this happening: The fake Xeno Executor installer campaign is an active Roblox-themed malware operation that uses gaming forums and Discord communities to lure victims into running...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
Campaign
H score39
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
CampaignAbout this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
Fake Gemini CLI and Claude Code SEO-poisoning infostealer campaign
Campaign
H score33
First: 22.05.2026 14:30
Last: 22.05.2026 14:30
Sources 1
About this happening:
Cyber threat actors ran a malicious SEO-poisoning campaign that impersonated Google Gemini CLI and Anthropic Claude Code to push malicious downloads. The operation...
Fake Gemini CLI and Claude Code SEO-poisoning infostealer campaign
CampaignAbout this happening: Cyber threat actors ran a malicious SEO-poisoning campaign that impersonated Google Gemini CLI and Anthropic Claude Code to push malicious downloads. The operation...
HeartlessSoul phishing and malvertising espionage campaign targeting aerospace firms and drone operators
Campaign
H score29
First: 11.05.2026 15:00
Last: 11.05.2026 15:00
Sources 1
About this happening:
The HeartlessSoul operation is using phishing and malvertising to target aerospace firms and drone operators, raising the risk of geospatial data theft from co...
HeartlessSoul phishing and malvertising espionage campaign targeting aerospace firms and drone operators
CampaignAbout this happening: The HeartlessSoul operation is using phishing and malvertising to target aerospace firms and drone operators, raising the risk of geospatial data theft from co...
Timeline
-
11.08.2026 21:36 2 articles · 2h ago
CERT-UA discloses Sandworm fake recruiter campaign targeting Ukrainian IT workers
Initial DisclosureCERT-UA disclosed a Russian state-linked social engineering campaign attributed to UAC-0145 within Sandworm and aimed at IT workers in Ukraine. The operation used fake recruiter outreach on job search sites, moved conversations to Telegram, invited victims to Zoom interviews, and pushed a poisoned WireGuard-based VPN and SourceForge-hosted lures designed to install malware and enable arbitrary command execution on the victim host. The campaign was assessed to have been ongoing since May 2026.
Show sources
- Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands — thehackernews.com — 11.08.2026 21:36
- Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands — thehackernews.com — 11.08.2026 21:36