Sandworm-linked UAC-0145 Uses Fake Job Offers to Deliver Trojanized WireGuard VPN Client (SopraVPN)
Sandworm-linked UAC-0145 Uses Fake Job Offers to Deliver (TL-2026-1988), also tracked as SopraVPN campaign, is a high-severity malware campaign, first published 2026-08-11. It is attributed to Sandworm (Russia) with high confidence, affects N/A (social-engineering delivery of a self-authored trojan, not a, maps to 13 MITRE ATT&CK techniques (T1027, T1036, T1053.005), and is covered by 9 detection rules and 12 indicators of compromise.
Key facts for TL-2026-1988
- Threat ID
- TL-2026-1988
- Also known as
- SopraVPN campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-08-11
- Last reviewed
- 2026-08-11
- Attribution
- Sandworm
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- information technology, telecoms
- Target regions
- ukraine
- Detection rules
- 9
- Indicators of compromise
- 12
Malware and tooling in Sandworm-linked UAC-0145 Uses Fake Job Offers to Deliver
Malware and tooling: SopraVPN, telegram, WireGuard
UAC-0145, a Russian GRU-affiliated Sandworm/APT44/Seashell Blizzard sub-cluster, has run a fake-recruiter social-engineering campaign against Ukrainian IT professionals and system administrators since at least May 2026. Victims lured via job sites, Telegram, and a Zoom 'interview' are pushed to download a trojanized WireGuard VPN client ('SopraVPN') from SourceForge that hides AES-256-GCM-encrypted PowerShell commands (Windows) or triggers a cURL-based secondary payload fetch (Linux) inside its own configuration file.
How Sandworm-linked UAC-0145 Uses Fake Job Offers to Deliver works
CERT-UA (advisory 6318863, published 2026-08-09) documented a multi-stage social-engineering operation run by UAC-0145, a sub-cluster of the Russian GRU-linked UAC-0002/Sandworm activity, tracked elsewhere as APT44 and Seashell Blizzard. Operators trawl legitimate Ukrainian job-search sites for IT professionals and system administrators, review candidate resumes, and make first contact through the site's built-in chat while posing as recruiters for the real IT firm ATLAS Business Group. The conversation is moved to Telegram, where a fabricated HR manager claiming to represent Sopra Steria Bulgaria (a real, unaffiliated European IT/consulting company) conducts a preliminary screening on work history and English proficiency, then schedules a Zoom videoconference with an English-speaking interviewer whose authenticity CERT-UA could not confirm (possibly AI-generated).
As part of a purported technical assessment, the fake employer emails the candidate a WireGuard VPN configuration file that is deliberately broken, then recommends the candidate instead install a custom 'SopraVPN' client, distributed from SourceForge project pages under the fake domain soprasteria-bg.com. The SopraVPN binary is a genuine WireGuard build modified by the attackers: it adds a non-standard 'SymmetricKey' configuration option whose value is BASE64-encoded AES-256-GCM ciphertext (nonce + ciphertext + authentication tag), and repurposes the 32-byte value normally used for the legitimate 'PrivateKey' field as the AES-256 decryption key. Once decrypted, the resulting PowerShell code is executed through WireGuard's own 'runScriptCommand' hook, giving the attacker command execution on the endpoint disguised as normal VPN client behavior. On Windows, the payload creates a scheduled task to fetch and run a second-stage payload; on Linux, the client uses cURL to pull an additional executable from attacker infrastructure over the already-established VPN tunnel. The PowerShell payload is further obfuscated with a custom BASE64 alphabet generated via a Fisher-Yates shuffle prior to encryption. As of public disclosure, all three known SourceForge project pages (soprabulgariavpn, sopravpn, soprasteriavpn) were unavailable.
CERT-UA and multiple outlets attribute the campaign with high confidence to UAC-0145/Sandworm/GRU, noting it is the third distinct Sandworm-linked operation disclosed since July 2026 (following a June/July 2026 ClickFix fake-CAPTCHA campaign against Ukrainian websites), consistent with a GRU cyber directorate running several parallel tracks against Ukrainian IT and telecommunications targets. No CVE or software vulnerability is involved; the entire chain relies on social engineering plus a trojanized, self-authored VPN client rather than exploitation of a flaw in upstream WireGuard.
MITRE ATT&CK techniques used in TL-2026-1988
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1684.001 Impersonation
Persistence
Execution
T1059.001 PowerShell; T1204.001 Malicious Link
Initial Access
Command and Control
Resource Development
T1583.001 Domains; T1585 Establish Accounts; T1587.001 Malware
Reconnaissance
Affected products and versions in Sandworm-linked UAC-0145 Uses Fake Job Offers to Deliver
- N/A (social-engineering delivery of a self-authored trojan, not a vulnerability) — Windows endpoints belonging to IT/sysadmin job candidates
Vulnerable versions: N/A - N/A (social-engineering delivery of a self-authored trojan, not a vulnerability) — Linux endpoints belonging to IT/sysadmin job candidates
Vulnerable versions: N/A
Remediation for Sandworm-linked UAC-0145 Uses Fake Job Offers to Deliver
Immediate actions
- Block/alert on the domain soprasteria-bg.com and the SourceForge project URLs (soprabulgariavpn, sopravpn, soprasteriavpn) at web/email gateways
- Restrict corporate resource access to managed endpoints enrolled in EDR with enforced security policy, per CERT-UA's recommendation
- Brief IT/sysadmin staff on the fake-recruiter pattern: job-site chat contact as 'ATLAS Business Group' -> Telegram HR screening as 'Sopra Steria Bulgaria' -> Zoom interview -> forced download of a 'custom corporate VPN client'
Workarounds
- Never accept VPN configuration files or VPN client software distributed outside verified, official vendor channels as part of a job interview or onboarding process
Longer-term hardening
- Deploy EDR/behavioral monitoring for PowerShell processes spawned by VPN client binaries or triggered via WireGuard's runScriptCommand mechanism
- Enforce application allowlisting so unsigned/unauthorized VPN clients cannot be installed or executed on managed endpoints
- Monitor for anomalous scheduled task creation immediately following installation of new VPN/network utility software
Timeline of Sandworm-linked UAC-0145 Uses Fake Job Offers to Deliver
- UAC-0145's fake-recruiter campaign against Ukrainian IT professionals and sysadmins begins, per CERT-UA's assessment that activity has run 'at least since May 2026' (exact start date approximate).
- A related UAC-0145 operation using ClickFix fake-CAPTCHA lures on compromised Ukrainian websites is disclosed, showing the same actor cluster running a parallel track (date approximate).
- CERT-UA publishes advisory 6318863, formally attributing the SopraVPN fake-recruiter campaign to UAC-0145/Sandworm/GRU.
- The Record (Recorded Future News) and Ukrainian outlet expert.com.ua publish coverage of the campaign.
- All three known SourceForge SopraVPN project pages (soprabulgariavpn, sopravpn, soprasteriavpn) are found unavailable/taken down as of public disclosure.
- The Hacker News and TechTimes publish further coverage corroborating CERT-UA's technical findings and attribution.
Sources cited for Sandworm-linked UAC-0145 Uses Fake Job Offers to Deliver
- Sandworm-Linked UAC-0145 Uses Fake Job Offers to Push Trojanized WireGuard VPN Client
- Соціальна інженерія у виконанні UAC-0145: компрометація у процесі працевлаштування
- Sandworm Recruiter Scam Targets Ukrainian Sysadmins, Deploys Hidden WireGuard Trojan
- Russian military hackers pose as recruiters to target Ukrainian IT workers
- UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware
- Кібератака під виглядом працевлаштування: CERT-UA викрила нову схему хакерів Sandworm
Threats related to Sandworm-linked UAC-0145 Uses Fake Job Offers to Deliver
Detection coverage for TL-2026-1988
As of 2026-08-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1988 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.