started · updated
Sandworm subgroup targets IT professionals via fake job interviews
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified a sophisticated social engineering campaign targeting IT professionals and system administrators. The operation, attributed to UAC-0145—a subgroup of the GRU-affiliated Sandworm hacking group—has been active since at least May 2026.
Attackers pose as recruiters from ATLAS Business Group and claim to be conducting screenings for Sopra Steria Bulgaria, a legitimate European consulting firm. The process involves moving conversations from job portals to Telegram, followed by Zoom video interviews with an English-speaking individual.
To complete a technical assessment, victims are instructed to use specific WireGuard configuration files to connect to a corporate VPN. When these files fail to connect, the attackers direct the targets to download a custom client called ‘SopraVPN’ from SourceForge. This client is a modified version of the WireGuard source code containing a non-standard ‘SymmetricKey’ configuration option, which functions as a backdoor to execute commands on the victim's system.
Entities
ATLAS Business Group · CERT-UA · GRU · Sandworm · Sopra Steria Bulgaria