negativeSYS.SOURCE: The Hacker News• 2026-08-12T00:06:47+05:30
Sandworm-Linked UAC-0145 Exploits Social Engineering via Fake Job Interviews to Deploy Malicious VPN
A Russian nation-state threat group, UAC-0145 linked to Sandworm, uses social engineering via fake job interviews with AI-generated personas to deploy a malicious VPN. The modified WireGuard-based SopraVPN allows attackers to execute arbitrary commands on victim systems through PowerShell and scheduled tasks.
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware.
CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,
*** END OF TRANSMISSION ***