CERT-UA has publicly disclosed a Sandworm-linked espionage campaign that targets IT professionals in Ukraine through fake job interview offers and trojanized WireGuard VPN clients — operations running since at least May 2026 and formally attributed by Ukrainian authorities to threat cluster UAC-0145, identified as a sub-group within the Russian military intelligence-linked Sandworm group known for the NotPetya attacks and multiple Ukraine power grid intrusions.
Trojanized WireGuard VPN as Primary Delivery Vector
Attackers posed as recruiters recruiting IT workers in Ukraine to install remote access tools under the guise of “job evaluation environments” — a highly deceptive vector given that legitimate system administrators actively use WireGuard. The compromised client delivered command execution capability and persistence on victim systems while appearing identical to legitimate VPN software.
Operation has been continuous since approximately May 2026, with targeting of Ukrainian IT professionals across government, military, and private sectors. CERT-UA first discovered the campaign when normal incident response reviews flagged suspicious VPN connections established through trojanized WireGuard clients that appeared authentic to administrators expecting legitimate software installations.
Attacker Strategy: Fake Recruiting for Remote Access Testing
The social engineering component targets system administrators specifically — individuals trained to evaluate new tools as part of their professional responsibilities. Attackers present themselves as recruiters seeking to set up “evaluation environments” where targets install provided VPN clients under the assumption these are standard testing tools from legitimate vendors. The setup process is designed to appear routine: administrators receive installation instructions that mirror official WireGuard deployment procedures, and the trojanized client connects to attacker-controlled infrastructure while appearing in system monitoring tools as a standard VPN configuration.
This methodology reflects Sandworm’s operational pattern of targeting individuals whose professional trust in legitimate security tools can be weaponized — the group exploits not just technical vulnerabilities but institutional trust in well-established infrastructure software to maintain access to Ukrainian government and military IT environments. CERT-UA published public disclosure of UAC-0145 attribution on August 11 with IoCs for organizations to monitor suspicious VPN configurations.
Defensive Actions for Affected Organizations
Organizations should verify all WireGuard installations against official binaries from wireguard.com, cross-check installed configurations against expected organizational deployment patterns, and flag any remote access connections to unknown WireGuard servers in network logs — particularly those established between May and August 2026 when the campaign was actively progressing. CERT-UA continues issuing security alerts with additional IoCs as their investigation of UAC-0145 operations expands, which organizations should monitor for updated detection guidance on sandworm-linked VPN-based access infrastructure.
