← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 12, 2026 · 09:04via Cyber Security News

Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals

Brief

Sandworm has turned the routine job interview into a route for compromising IT workers.

The campaign uses convincing recruiter conversations, live video calls and a booby-trapped virtual private network client to reach people who may hold privileged access to company systems.

The operation targets system administrators and other IT specialists after attackers study their resumes on job-search sites.

It begins with a message from a supposed employer, moves into a chat and then presents a technical assessment that appears to need a corporate VPN connection.

CERT-UA analysts identified the activity as UAC-0145, a Sandworm-linked subcluster also known as APT44 and Seashell Blizzard.

The agency said the activity has continued since at least May 2026, showing how staged recruitment fraud can bypass technical suspicion.

Read more on Cyber Security News