Sandworm-Linked Actors Use Fake Job Interviews to Deploy Malicious VPN Client
UAC-0145, a threat group linked to Russia's Sandworm, is exploiting the trust IT professionals place in recruitment processes by impersonating hiring managers and directing victims to download a trojanized WireGuard VPN client hosted on SourceForge. Because the software appears legitimate and originates from a recognized hosting platform, victims are less likely to question its authenticity. Once installed, the modified VPN grants attackers the ability to execute arbitrary commands, effectively providing full remote control of the compromised system. This attack demonstrates how social engineering combined with software supply chain abuse can bypass traditional technical defenses. IT professionals—often trusted with privileged access—represent high-value targets whose compromise can cascade across entire organizations.
Tactical Insight
Immediate actions
- Train all IT staff to independently verify recruiter identities and never download software provided during unsolicited interview processes.
- Establish an approved software allowlist and block execution of unapproved VPN clients or unsigned binaries on corporate and personal work devices.
Supply chain & configuration controls
- Verify cryptographic hashes of all downloaded software against official vendor sources before installation, even from reputable platforms like SourceForge or GitHub.
- Deploy application control policies (e.g., via AppLocker or WDAC) to prevent execution of unauthorized or modified network utilities.
- Require that all VPN software deployments go through an internal IT review and approval process before use.
Detection measures
- Monitor for anomalous outbound command-and-control traffic originating from VPN client processes using endpoint detection and response (EDR) tooling.
- Alert on new or unrecognized VPN installations appearing on endpoints, particularly those not deployed through sanctioned channels.
- Implement behavioral analytics to flag unusual command execution patterns spawned by network-related processes.