Sandworm Cyber Threats Target IT Professionals A group linked to Sandworm is using fake job interviews as a tactic to trick IT professionals into installing malware. Ukraine's CERT-UA has identified this activity under UAC-0145, a subcluster of UAC-0002, also known by names like Sandworm, APT44, and Seashell Blizzard. What sets this operation apart is its combination of a realistic recruitment process with a modified version of a trusted VPN tool.

Instead of relying on basic phishing emails, the attackers study candidates' resumes from job-search platforms and build credibility through several steps before deploying malware. The provided VPN is designed to fail, causing candidates to download a custom client called SopraVPN from SourceForge via the spoofed domain, making it appear legitimate.

It then decrypts embedded PowerShell scripts using this key and passes them to WireGuard's runScriptCommand mechanism, typically used for processing configuration directives like PostUp. Instead of using standard Base64 encoding, the PrivateKey and PublicKey fields utilize a custom alphabet created through a Fisher-Yates shuffle. On Windows, PowerShell commands decrypt a scheduled task named Microsoft\Windows\ApplicationData\Microsoft, which downloads an additional payload from an attacker-controlled URL.

Utilize ANY.RUN's in-browser data inspection for faster detection and investigation, enhancing your SOC and reducing Mean Time To Repair (MTTR).