Russian state-backed hackers are using deceptive job offers as a method to infiltrate IT systems with malware. This alarming campaign, identified by the Computer Emergency Response Team of Ukraine (CERT-UA), targets IT professionals by posing as legitimate recruiters.
How the Deception Unfolds
The campaign, attributed to a threat group known as UAC-0145, involves hackers impersonating representatives from IT companies. These attackers contact potential victims through job search platforms, initially engaging them in conversation via online chat before moving to encrypted messaging apps like Telegram.
During these interactions, hackers pretend to be HR managers from recognized companies, such as Sopra Steria Bulgaria. This is followed by a supposed Zoom interview, which may involve an AI-generated persona posing as a genuine interviewer.
Technical Manipulation Tactics
Following the initial engagement, victims receive emails with instructions for a technical interview, including files for accessing a corporate VPN. When these files fail to connect, the victims are directed to download a fake VPN client called SopraVPN, falsely presented as a legitimate solution from Sopra Steria Bulgaria.
The manipulated VPN client is engineered from the WireGuard source code, featuring a modified configuration that allows hackers to execute commands on the victim’s device without detection. This includes creating scheduled tasks to download further malicious payloads.
Security Recommendations and Broader Implications
CERT-UA advises IT professionals to remain vigilant against such social engineering tactics. Organizations should restrict access to corporate networks to managed devices equipped with robust security measures, alongside implementing continuous monitoring practices.
This campaign highlights a broader trend of nation-state actors, including those from China, Iran, and North Korea, employing fake recruitment strategies to breach targeted systems. The ongoing threat underscores the importance of comprehensive cybersecurity measures to protect sensitive information.
The recent activities of Russian hackers underline the evolving cyber threat landscape, necessitating heightened awareness and proactive defense strategies within the cybersecurity community.
