Sandworm APT44 Targeting Ukrainian IT Professionals via WireGuard VPN Misuse
The Russian GRU-affiliated threat group Sandworm, operating under the UAC-0145 cluster, is conducting a highly targeted social engineering campaign against Ukrainian IT professionals. Utilizing fraudulent recruitment communications, the actors distribute malicious payloads to high-value technical targets. A critical technical component involves the misuse of WireGuard VPN configurations to establish unauthorized access and bypass perimeter defenses. This method facilitates lateral movement and provides persistent connectivity within sensitive professional environments, enabling intelligence gathering and potential disruption of critical digital infrastructure.
UAC-0145 Sandworm ClickFix CAPTCHA and Ethereum-based SMARTAXE C2
UAC-0145, a sub-cluster of the GRU-linked Sandworm group, is employing "ClickFix" social engineering to compromise Ukrainian and global targets. Attackers use compromised websites to present fraudulent CAPTCHA prompts, tricking users into manually executing malicious PowerShell commands. Once established, the group deploys a multi-stage Windows payload suite—including GHETTOVIBE and FREAKYPOLL—and the COWARDDUCK Android backdoor. C2 resilience is achieved via SMARTAXE, which utilizes Ethereum smart contracts and the eth_call function for dynamic domain resolution. Data exfiltration targets Signal, WhatsApp, and browser credentials via Dropbox and RSYNC, facilitating high-impact intelligence collection.