Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

August 11, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: IT professionals and system administrators
Incident: A social engineering campaign using fake job interviews to deploy a modified WireGuard VPN for remote command execution.
Impact: Full system compromise and remote control of targeted IT infrastructure.
Attacker: UAC-0145 (Sandworm / APT44)
Analysis: The UAC-0145 group, linked to Sandworm, is masquerading as recruiters to target IT specialists through a sophisticated social engineering pipeline. By blending legitimate-looking Zoom calls with a modified WireGuard VPN client, they trick victims into installing backdoored software. This allows the attackers to execute remote commands on the victim’s system while appearing to be a standard corporate connectivity tool.
Recommendations: Verify recruiter identities through official company channels before downloading any software.; Avoid installing VPNs or technical assessment tools from unofficial repositories like SourceForge.; Implement strict application whitelisting and endpoint monitoring on administrative workstations.
Source: The Hacker News / CERT-UA

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *