Sandworm, a notorious cyber threat entity, is leveraging job interviews as a vector to compromise IT professionals. The group is utilizing seemingly legitimate recruitment interactions, including video calls and compromised VPN clients, to target individuals with access to sensitive company resources.
The Methodology Behind the Attack
This elaborate scheme involves targeting IT specialists, such as system administrators, after scrutinizing their resumes on job portals. The attack begins with communication from a fake employer, progressing through chat and video calls, and culminating in a technical assessment that ostensibly requires a corporate VPN connection.
According to CERT-UA analysts, the activity, identified as UAC-0145, is linked to the Sandworm subcluster known as APT44 or Seashell Blizzard. This campaign, active since at least May 2026, demonstrates how carefully constructed recruitment fraud can circumvent technical defenses.
Technical Execution of the Attack
The attackers impersonate IT recruiters, initiating contact through job-site chats and Telegram, followed by English-language screenings and Zoom interviews. The candidates are then emailed instructions for a technical test, which includes downloading WireGuard configuration files.
When these configurations fail, a VPN client, SopraVPN, is suggested. This application, a modified version of WireGuard, is the true trap. It includes a hidden configuration setting, SymmetricKey, which decrypts embedded PowerShell code using a private key, leading to further system compromises.
Implications and Preventive Measures
The campaign’s strength lies in its social engineering tactics, making the request to install software appear routine. Such attacks emphasize the need for IT professionals to verify employers through official channels before participating in interviews or installing software.
For organizations, especially in telecommunications and IT sectors, it is critical to restrict access to corporate resources to managed devices with strong endpoint protection and monitoring. Additionally, any requests for custom VPN installations or external downloads should be scrutinized.
CERT-UA underscores the importance of educating staff about these recruitment scams. Legitimate hiring processes should not require deviations from established software and device protocols. Security teams should also establish clear reporting processes for suspicious recruitment activities to prevent the spread of malicious software.
In conclusion, while the Sandworm campaign highlights the evolving nature of cyber threats, it also serves as a reminder of the importance of vigilance and robust security practices in safeguarding IT infrastructures.
