← Back to Daily Briefing (#LazarusGroup)

The Russian GRU-affiliated threat group Sandworm, operating under the UAC-0145 cluster, is conducting a highly targeted social engineering campaign against Ukrainian IT professionals. Utilizing fraudulent recruitment communications, the actors distribute malicious payloads to high-value technical targets. A critical technical component involves the misuse of WireGuard VPN configurations to establish unauthorized access and bypass perimeter defenses. This method facilitates lateral movement and provides persistent connectivity within sensitive professional environments, enabling intelligence gathering and potential disruption of critical digital infrastructure.

  • Campaign Overview: Targeted Social Engineering
    • Primary Target: Ukrainian IT sector and specialized technical personnel.
    • Objective: Intelligence gathering, lateral movement, and disruption of critical infrastructure.
    • Timeline: Ongoing activity observed since at least May 2026.
  • Attack Mechanics: Fraudulent Recruitment Lures
    • Delivery Method: Sophisticated social engineering via fake recruitment emails and messaging.
    • Vector: Exploitation of professional trust through fraudulent job opportunities.
    • Payload: Deployment of malicious tools, likely Remote Access Trojans (RATs) or info-stealers.
  • Technical Deep Dive: WireGuard VPN Abuse
    • Protocol Misuse: Leveraging WireGuard VPN configurations to establish unauthorized network tunnels.
    • Perimeter Bypass: Bypassing traditional network defenses by masquerading as legitimate VPN traffic.
    • Persistence: Establishing long-term access to sensitive networks via compromised VPN identities.
  • Threat Actor Profile: Sandworm (APT44 / UAC-0145)
    • Attribution: Identified as a GRU-linked threat actor (APT44).
    • Cluster Designation: Operating under the specific threat cluster UAC-0145.
    • Profile: Highly sophisticated actor specializing in state-sponsored disruptive operations.
  • Detection and Mitigation Strategies
    • Zero Trust Implementation: Moving beyond perimeter-based security to validate all VPN-connected sessions.
    • Communication Scrutiny: Heightened verification processes for unsolicited professional communications and attachments.
    • Network Monitoring: Real-time auditing of WireGuard configurations and anomalous VPN tunnel behavior.

Related posts

  1. blackhatnews.tokyo — Sandworm、偽装WireGuard VPNクライアントでITプロを標的に
  2. blackhatnews.tokyo — Sandworm、偽の求人面接でトロイの木馬化したWireGuard VPNをIT担当者に配布
  3. techjacksolutions.com — Sandworm / UAC-0145 (Multi-Platform Campaign, No Single Vendor), Vulnerability Rollup (2026-07-19)
  4. The Record by Recorded Future — Russian military hackers pose as recruiters to target Ukrainian IT workers
  5. feeds.feedburner.com — Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
  6. bleepingcomputer.com — Sandworm hackers target IT pros with trojanized WireGuard VPN client
  7. Mallory
  8. Zscaler
  9. Facebook
  10. Technoid
  11. En
  12. Reddit
  13. Cybersecurity-help
  14. Cisoseries

LINK COPIED TO CLIPBOARD