Russian military hackers pose as recruiters to target Ukrainian IT workers
ID: 9b175ecb-9f3c-5321-a860-5325c0e4b4da
STIX ID: report--9b175ecb-9f3c-5321-a860-5325c0e4b4da
Feed Name: The Record from Recorded Future News
Ukraine's CERT-UA reports a Sandworm-linked campaign targeting Ukrainian IT professionals by posing as recruiters; attackers used job-site outreach, Telegram and Zoom interviews, and crafted emails to persuade candidates to install a custom WireGuard-based VPN (SopraVPN) hosted on SourceForge. The VPN client was modified to allow execution of embedded (sometimes encrypted) commands, enabling covert compromise of victims' systems; CERT-UA did not disclose victim counts or attackers' ultimate objectives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
