Protect.Computer
NEWS

Sandworm Hackers Use Fake Job Interviews to Plant Backdoor VPN

· 1 min read · Malicious byte Got hacked
Sandworm Hackers Use Fake Job Interviews to Plant Backdoor VPN

A sub-cluster of the Russian state-sponsored hacking group Sandworm, tracked by Ukraine’s Computer Emergency Response Team (CERT-UA) as UAC-0145, has been running a sustained fake-recruitment campaign since at least May 2026. The attackers target system administrators and IT professionals, studying their résumés on job sites and reaching out directly on LinkedIn and similar platforms. Once contact is established, conversations move to Telegram, where candidates are invited to a Zoom “technical interview” with a supposed international IT company.

During the interview, which is conducted in English, the candidate receives a mock assignment that requires connecting to a “corporate VPN” to complete the task. The attackers provide a WireGuard configuration file and instructions to download a VPN client called “SopraVPN” from SourceForge. The page is designed to look like a legitimate tool from Sopra Steria, a real European IT firm, complete with a lookalike domain (soprasteria-bg[.]com) hosted by the attackers. The downloaded client is a trojanized WireGuard build that includes a malicious nonstandard protocol component. Once installed, it gives the attackers persistent remote access and the ability to run commands on the victim’s machine — all while appearing to be a normal corporate VPN. CERT-UA says that in observed cases, the attackers went so far as to create realistic email addresses mimicking Sopra Steria’s Bulgarian office to make the outreach look credible.

How to check if you’re affected

Affected products include any Windows or Linux system where the “SopraVPN” WireGuard client was installed following a recruiter interaction on Telegram or LinkedIn. If you or someone on your team recently participated in an unsolicited IT job interview that ended with a VPN installation requirement, check for the following indicators of compromise: the domain soprasteria-bg[.]com in your WireGuard configuration or browser history, and the file SopraVPN in your downloads or installed applications. Any affected systems should be treated as fully compromised and rebuilt from a clean image.

Sources

Related reading