Sandworm targets IT pros with trojanized VPN client
🔒 A Ukrainian CERT report details a social-engineering campaign by a Sandworm-linked cluster, UAC-0145, targeting system administrators and IT professionals with fake job offers and interviews. Attackers move conversations to Telegram, conduct Zoom interviews, then instruct candidates to install a trojanized WireGuard client named "SopraVPN" from SourceForge. The modified client includes a nonstandard SymmetricKey option that decrypts and executes embedded PowerShell on Windows and retrieves executables via VPN on Linux, while using a custom Base64 alphabet to hinder analysis.
