Sandworm Targets IT Pros With Trojanized WireGuard Client
CERT-UA links UAC-0145 to fake recruiting ops targeting sysadmins since May. The lure delivers a trojanized WireGuard client with remote command execution.
A campaign quietly running since at least May has been using fake job offers to get system administrators and IT professionals to install a backdoored WireGuard VPN client. Ukraine’s computer emergency response team, CERT-UA, has linked the operation to UAC-0145 — a persistent subgroup within Sandworm, the Russian GRU-affiliated threat actor also tracked as APT44. BleepingComputer reported the campaign details alongside The Hacker News’s coverage of CERT-UA’s attribution to UAC-0145.
The delivery mechanism is deliberate in its simplicity: a recruiter contacts the target, the conversation progresses toward an opportunity, and eventually leads to a software download. The installer presents as WireGuard but includes an additional component that provides the attacker with a channel to execute commands on the compromised machine.
Why Sysadmins
IT workers carry disproportionate access. A compromised sysadmin’s workstation is often three lateral steps from domain controllers, backup infrastructure, and production environment credentials — the kind of access that would take weeks to establish through phishing email chains against ordinary employees.
The choice of WireGuard as the delivery vehicle is not incidental. It’s a tool IT professionals are expected to install, adjust, and share within their organizations. A recruiter suggesting a prospective employer’s VPN client for an interview environment is not an obviously suspicious request. That’s the lure’s value: not deception through technical complexity, but through plausibility.
The Recruiter Playbook, Imported
Impersonating recruiters to target technical professionals is a tactic most associated with North Korea’s Lazarus Group, whose Operation Dream Job documented this pattern years ago. Russia’s adoption of the same template — specifically against Ukrainian IT workers — suggests the approach has delivered consistent results worth replicating. The barrier to entry is low: a credible-looking persona and familiarity with what the target’s industry considers routine.
CERT-UA frames UAC-0145 as a cluster focused on social engineering against technical targets in Ukraine, consistent with Sandworm’s documented interest in organizations that touch critical infrastructure. The same group has been tied to campaigns against energy, telecom, and government sectors across Ukraine since the 2022 invasion. This campaign extends the targeting to the people who maintain those systems.
What This Means for Defenders
The technical substance here is not a zero-day or an unpatched vulnerability — it’s an operational pattern that succeeds when software provenance isn’t verified. A few points worth taking seriously:
Software provenance matters. Any installer arriving through an external contact — recruiter, contractor, third-party vendor — should be hash-verified against an official source before it runs in a privileged environment. For WireGuard, official releases and their checksums are published at wireguard.com. A ZIP from a LinkedIn message is not an adequate substitute.
Privileged access workstations reduce blast radius. If a sysadmin’s daily driver is also their administrative console, a single compromise gives attackers everything. Isolating privileged operations to dedicated machines — not browsing the web, not reading external email — limits what’s reachable from a compromised endpoint.
Recruitment contact as a threat vector warrants process. Organizations with IT staff who work on infrastructure connected to critical sectors should establish a verification step for software installs initiated by external parties. One secondary-channel confirmation before running an installer is not a high-friction ask given what’s at stake.
Organizations with direct Ukrainian nexus — government entities, defense contractors, energy sector operators — can engage CERT-UA directly for indicators of compromise and incident response support. For others: treat this as a signal about a targeting pattern that’s already been proven effective enough to run for three months without disruption, not as a problem that stops at a particular border.
The tools Sandworm reaches for are, increasingly, the ones a careful IT professional would already have reason to trust. That’s the pattern worth watching.
Found this useful? Share it.


