# Russia's Sandworm Is Running Fake Tech Interviews to Deploy a Poisoned VPN Client
The bait is perfectly calibrated: a recruiter finds your CV on a job site, slides into your DMs on Telegram, schedules a real Zoom call with a real-seeming interviewer, sends you a professional onboarding packet, and asks you to connect to the company VPN before a technical assessment. By the time something feels off, the damage is done.
Ukraine's CERT-UA disclosed this week that UAC-0145, a subgroup of Russia's GRU-affiliated Sandworm, has been running exactly this operation against Ukrainian IT workers since at least May 2026. The targets are sysadmins and IT specialists — people whose access, once compromised, opens doors across entire organizations.
## The Setup Is Meticulous
The campaign begins on job boards. Attackers, posing as recruiters from "ATLAS Business Group," contact candidates who have posted their resumes, then migrate the conversation to Telegram. From there, a purported HR manager for Sopra Steria Bulgaria — a real European consulting firm — takes over, asking standard screening questions and discussing English proficiency.
A Zoom video call follows. By all accounts, the interview proceeds normally, with an English-speaking man in his thirties conducting the session. What remains unclear — and this detail deserves more attention than it has received — is whether that man is a real human participant or an AI-generated synthetic persona. CERT-UA explicitly flagged the uncertainty. This isn't paranoia. Deepfake video in live calls has been a documented technique in financial fraud for over two years. Its appearance in a nation-state espionage campaign targeting wartime infrastructure workers represents a meaningful escalation.
After the Zoom call, candidates receive an email with what looks like legitimate onboarding materials: WireGuard configuration files for connecting to the "corporate VPN." Naturally, the connection fails. The attackers then recommend a fix — download "SopraVPN," helpfully hosted on SourceForge, linked through a lookalike domain designed to mimic the real Sopra Steria Bulgaria site.
## The Technical Trick Is Elegant
The payload is not some novel malware. That is precisely the point.
SopraVPN is a compiled fork of the legitimate WireGuard open-source codebase with one critical modification: it adds support for a non-standard SymmetricKey configuration option. The value of that field contains BASE64-encoded data — a nonce, ciphertext, and authentication tag — encrypted with AES-256-GCM. The decryption key is derived from the VPN's own PrivateKey field.
The decrypted payload is PowerShell code, which gets passed to WireGuard's existing runScriptCommand mechanism — the same one WireGuard legitimately uses to execute commands specified by the PostUp option. No shellcode injection, no RCE exploit. Just a trusted application running commands it was always capable of running, with the instructions hidden in a configuration value that looks unremarkable to a human reviewer.
On Windows, that PowerShell payload creates a scheduled task that fetches a secondary payload from attacker-controlled infrastructure. On Linux, the variant uses cURL to pull the executable directly. CERT-UA has not publicly confirmed what the second-stage payload does.
The use of SourceForge as a delivery platform is also deliberate. It is a trusted, long-standing open-source host. Security tooling that blocks known-malicious domains will not catch a download from sourceforge.net. The specific projects — soprabulgariavpn, sopravpn, and soprasteriavpn — appear to have been pulled offline since CERT-UA's disclosure, but the infrastructure pattern will resurface.
## Who Gets Hurt When a Sysadmin Falls
The choice of target matters. Ukrainian IT workers administering critical systems are exactly the right population if your goal is persistent, low-noise access to networks that matter — government agencies, energy companies, communications infrastructure.
A sysadmin who installs a trojanized VPN client and connects to their work network from home has just given the attackers a foothold inside the perimeter, authenticated through a trusted user's credentials, from a machine that probably has elevated privileges and is already trusted by internal monitoring systems. The scheduled task persistence means the implant survives reboots. The encrypted command channel means it survives naive traffic inspection.
This is not about one compromised workstation. This is about what that workstation can see, reach, and do.
---
## HackWire Analysis
Sandworm has been running variations of this playbook since before the full-scale invasion of Ukraine in 2022, but the evolution of this campaign reflects a more patient, resource-intensive approach than their earlier blunt-force destructive attacks like NotPetya or the 2022 Industroyer2 targeting of Ukrainian substations.
What stands out is the convergence of three trends in a single operation. First, the abuse of legitimate open-source tooling. Weaponizing WireGuard's PostUp mechanism requires no zero-day, no exploit kit purchase, and produces no signature that most AV will flag — because the binary is a compiled fork of a well-regarded open-source project. This mirrors the broader trend of APT actors shipping "living-off-the-land" implants that wrap legitimate software rather than deploying custom malware from scratch.
Second, the possible use of AI-generated video in the interview phase is the underreported part of this disclosure. If confirmed, it marks the point where deepfake social engineering moves from financial fraud — where it has already caused documented eight-figure losses — into state-sponsored espionage against wartime critical infrastructure. The verification heuristics that help people spot fake recruiters (reverse image search, LinkedIn cross-referencing) stop working when the face was never real to begin with.
Third, Sandworm is deliberately targeting the humans who hold the keys rather than hunting for unpatched software vulnerabilities. As Ukrainian network defenders have hardened their perimeters through three years of active conflict, the attack surface for technical exploits has narrowed. The attack surface for a tired sysadmin who gets a plausible job offer has not.
For defenders: VPN client binaries from any source outside official package repositories should be treated as untrusted, full stop — regardless of how legitimate the delivery chain appeared. WireGuard configurations received via email deserve the same scrutiny as macros in Office documents. And any organization whose staff may be targets of recruitment-themed social engineering should be briefing employees specifically on this campaign pattern, not just generic phishing hygiene.
The job board to Telegram to Zoom to fake VPN pipeline is repeatable and scalable. Expect variants.
— HackWire Editorial
---
## Related Coverage