Sandworm poses as recruiters to target Ukrainian IT workers
The campaign shifts supply-chain risk from software dependencies to the engineers themselves, and the technique is transferable.
TL;DR
Russia's GRU-linked Sandworm unit has been running a fake recruitment campaign targeting Ukrainian IT workers since at least May, CERT-UA reported Saturday. The attackers mine legitimate Ukrainian job boards for system administrators and developers, then shepherd candidates through staged HR screening on Telegram and Zoom before directing them to install a trojanized WireGuard VPN client called SopraVPN, hosted on SourceForge. Once installed, the app executes encrypted malicious commands embedded in VPN configuration files. The operation (which uses a credible front company, Atlas Business Group, and invokes a real IT services firm, Sopra Steria Bulgaria) represents a methodical expansion of Sandworm's social-engineering playbook from military targets to the IT workforce whose access multiplies downstream compromise paths.
CERT-UA's disclosure describes a campaign that is patient, multi-stage, and designed to survive scrutiny. The attackers don't just spray job-site messages, they review résumés, conduct live screening interviews, and invest weeks shepherding candidates toward the payload. The trojanized VPN is hosted on SourceForge and served from a site impersonating a legitimate IT firm. The malicious commands are encrypted inside WireGuard configuration files, so a cursory inspection of the installer or its config wouldn't reveal anything obviously hostile. This isn't a smash-and-grab credential phish; it's a targeted compromise pipeline built to convert IT professionals into persistent access points.
What's different about this campaign
Sandworm has spent years targeting Ukrainian military personnel and government agencies with social-engineering lures, fake Army+ apps, charity-themed malware, and Signal-borne documents. This campaign differs in target and technique. System administrators and developers aren't the end target; they're the supply chain. Compromising an IT worker who has legitimate access to corporate networks, source repositories, or cloud infrastructure yields the same downstream reach as compromising a software update pipeline, but with less operational friction. The technique is transferable beyond Ukraine. Any adversary with the patience to run a multi-week fake-recruitment funnel and the tradecraft to stand up credible front companies can adapt it.
The compliance and operational surface
For compliance directors and security teams, the immediate question is whether existing supply-chain risk programs account for this vector. Most third-party risk assessments focus on software provenance, not the hiring funnel. A developer compromised through a fake job interview isn't caught by SBOM checks or vendor questionnaires. The mitigations are old ones, executed more rigorously: endpoint detection that flags anomalous process behavior from VPN clients, network segmentation that treats developer workstations as untrusted entry points, and security awareness that treats job-site outreach with the same suspicion applied to unsolicited email attachments. That last one is harder than it sounds, the fake interview is the lure, and it's a good one.
Published ·Updated ·Deep Fathom