Russian nation-state threat actors, specifically the UAC-0145 subgroup of Sandworm, are conducting a social engineering campaign targeting IT workers in Ukraine. The attackers pose as recruiters, using fake job interviews as a ruse to trick victims into installing a malicious VPN client. This client has the capability to execute commands, potentially granting the attackers remote access to the compromised systems. The Computer Emergency Response Team of Ukraine (CERT-UA) has attributed this activity to UAC-0145, a threat cluster linked to the Sandworm group1. The use of social engineering tactics to gain access to IT systems highlights the evolving threat landscape, where state-aligned actors are increasingly using sophisticated methods to achieve their goals. This shift in tactics requires a different approach to threat modeling, one that takes into account the geopolitical motivations of the attackers. So what matters to practitioners is that they must now consider the potential for state-sponsored attacks when assessing their organization's security posture.
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
⚠️ Critical Alert
Why This Matters
State-aligned activity involving Russia shifts the threat model from criminal to geopolitical — different playbook required.
References
- The Hacker News. (2026, August 11). Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands. The Hacker News. https://thehackernews.com/2026/08/sandworm-linked-uac-0145-uses-fake-job.html
Original Source
The Hacker News
Read original →