Fake job interviews with AI recruiter: Sandworm hackers plant VPN trap for IT professionals

Fake job interviews with AI recruiter: Sandworm hackers plant VPN trap for IT professionals

The Sandworm group, linked to Russian military intelligence, has been running a campaign since May 2026 to compromise IT professionals in Ukraine through fake job interviews. CERT-UA, which tracks the threat as UAC-0145, disclosed the details.

The attackers operate through job search websites: after reviewing a candidate's resume, they reach out on behalf of an IT company, such as ATLAS Business Group. Initial contact happens via built-in chat, then the conversation moves to the Telegram messenger, where a purported HR manager claiming to represent the Bulgarian consulting firm Sopra Steria Bulgaria speaks with the victim.

During the exchange, general work questions and English proficiency are discussed, after which the candidate is invited to a Zoom video conference. According to CERT-UA, an English-speaking man aged 30–35 does appear on the call, but it remains unclear whether he was a real participant or a synthetic persona generated by artificial intelligence.

In parallel, instructions for a technical interview arrive by email: configuration files for connecting to a corporate VPN via WireGuard, plus a link to a second Zoom meeting where the test is supposedly monitored. When the candidate tries to connect, errors occur, prompting the attackers to recommend downloading a custom VPN client called SopraVPN hosted on SourceForge. The link mimics the official Sopra Steria Bulgaria website through the domain soprasteria-bg[.]com.

Researchers at The Hacker News identified three related SourceForge projects — soprabulgariavpn, sopravpn, and soprasteriavpn, the latter described as an "open-source corporate VPN solution for business." Installing such software gives hackers the ability to execute commands on the compromised machine, making the attack especially dangerous for system administrators and IT professionals with access to critical infrastructure.

The campaign remains ongoing, and CERT-UA urges employers and job seekers to verify the authenticity of recruiter contacts, especially when they suggest installing third-party software or following links to external resources.

Tags: Security
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate