Sandworm hackers target IT pros with trojanized WireGuard VPN client

Sandworm Hackers Target IT Pros with Trojanized WireGuard VPN Client

A sophisticated social engineering campaign attributed to the Russian threat group Sandworm has been targeting system administrators and IT professionals with fake job offers, leaving many wondering how these skilled hackers are able to breach even the most secure networks. The Ukrainian Computer Emergency Response Team (CERT-UA) has revealed a detailed report on the tactics used by UAC-0145, a sub-cluster of Sandworm (APT44), which poses as IT companies and recruiters to gain access to victims’ systems.

The attackers meticulously study their targets’ resumes uploaded on job sites before initiating direct contact through Telegram. They then arrange video interviews over Zoom, during which they instruct the candidates to connect to a corporate VPN using WireGuard. In one observed case, the attacker impersonated the international IT firm Sopra Steria, using email addresses similar to those used by the company’s Bulgarian office.

Once victims have connected to the VPN, they are prompted to download a modified WireGuard-based client called “SopraVPN” from SourceForge. The trojanized client supports a malicious configuration option that decrypts and executes embedded PowerShell code. On Windows, this code creates a scheduled task and downloads an additional payload from the Internet, while on Linux it uses cURL to retrieve another executable from attacker-controlled infrastructure through the VPN.

What’s particularly concerning is how Sandworm has managed to evade detection by replacing WireGuard’s standard Base64 decoding with a custom, dynamically generated alphabet. This rendering of key strings unreadable makes it challenging for security analysts to analyze the PowerShell code and identify potential malicious activity.

The CERT-UA has advised telecommunications providers and IT companies to restrict corporate resource access to managed devices protected by Endpoint Detection and Response (EDR) solutions, even when employees use personal equipment. APT44’s notorious track record of targeting critical infrastructure and government entities in Ukraine and other countries should serve as a warning to organizations worldwide.

This campaign highlights the importance of vigilance in protecting against social engineering attacks. Even with robust security measures in place, attackers can still gain initial access using valid credentials, which then enables them to breach defenses and execute malicious activities. As we continue to face an increasingly sophisticated threat landscape, it’s essential that organizations prioritize employee education and awareness programs to prevent such tactics from succeeding.

In light of this campaign, IT professionals should exercise extreme caution when interacting with job offers or suspicious emails, especially if they involve connecting to a VPN or downloading software from unverified sources. By staying informed and up-to-date on the latest threats, we can better protect ourselves against these kinds of attacks.


Source: Bleeping Computer — 2026-08-11