logo

Russian military hackers pose as recruiters to target Ukrainian IT workers

ID: 9b175ecb-9f3c-5321-a860-5325c0e4b4da

STIX ID: report--9b175ecb-9f3c-5321-a860-5325c0e4b4da

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2026-08-10

Date Updated: 2026-08-10

...
...

Ukraine's CERT-UA reports a Sandworm-linked campaign targeting Ukrainian IT professionals by posing as recruiters; attackers used job-site outreach, Telegram and Zoom interviews, and crafted emails to persuade candidates to install a custom WireGuard-based VPN (SopraVPN) hosted on SourceForge. The VPN client was modified to allow execution of embedded (sometimes encrypted) commands, enabling covert compromise of victims' systems; CERT-UA did not disclose victim counts or attackers' ultimate objectives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.