Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

A New Twist in Social Engineering Attacks: Sandworm-Linked Group Uses Fake Job Interviews to Spread Malware

A sophisticated group linked to the notorious Sandworm hacking collective has been using fake job interviews as a ruse to trick unsuspecting victims into installing malware on their devices. According to reports, this new tactic involves pushing a VPN (Virtual Private Network) that allows attackers to remotely execute commands on compromised systems.

The scheme is believed to be part of an ongoing campaign by the UAC-0145 group, which has been active in the threat landscape for some time. What’s particularly disturbing about this latest development is how convincing the fake job interviews are – victims are reportedly being told that they’ve been selected for a lucrative position at a well-known company and that the VPN installation is necessary to complete the hiring process.

The malware itself, which has been described as a “VPN” in disguise, allows attackers to not only monitor but also control compromised systems. This means that once installed, it’s likely being used to facilitate further attacks or even establish a backdoor for future exploitation. The fact that this is being done through a seemingly innocuous VPN installation raises serious concerns about the vulnerability of corporate networks and individual devices.

The UAC-0145 group’s tactics are particularly noteworthy because they illustrate the evolving nature of social engineering attacks. By using fake job interviews as a lure, these attackers are able to bypass traditional security measures and gain trust with their victims. This approach also underscores the growing importance of employee education in cybersecurity – companies must ensure that their staff is aware of such tactics and knows how to respond if approached by suspicious individuals.

While it’s unclear what the ultimate goals of this campaign are, experts warn that this type of attack can have far-reaching consequences for both individuals and organizations. If left unchecked, it could lead to data breaches, system compromise, or even the installation of more malicious software on compromised devices.

As a result, it’s essential for users to exercise extreme caution when faced with unsolicited job offers or requests for VPN installations. Always verify the authenticity of such requests through multiple channels and never install software from unknown sources – your device’s security is only as strong as its weakest link. By staying vigilant and taking proactive measures to protect yourself, you can significantly reduce the risk of falling victim to these types of attacks.


Source: The Hacker News — 2026-08-11