Actor Profile

Sandworm (also tracked as APT44, UAC-0145 sub-cluster) is a Russian-linked advanced persistent threat group notorious for targeting critical infrastructure and government entities, particularly in Ukraine and other countries. This actor is characterized by sophisticated social engineering capabilities and custom malware development. In this campaign active since at least May 2026, Sandworm targets IT professionals and system administrators through elaborate fake recruitment operations, demonstrating a shift toward supply-chain style attacks by compromising high-value IT personnel who maintain access to sensitive corporate networks.

TTPs (Tactics, Techniques, Procedures)

The campaign employs multi-stage social engineering beginning with reconnaissance of job site resumes, followed by direct contact via Telegram and Zoom video interviews conducted in English. Initial access is achieved through trojanized WireGuard VPN clients distributed under the guise of technical interview assignments. The modified client (branded "SopraVPN") includes a malicious non-standard "SymmetricKey" configuration option that decrypts and executes embedded PowerShell code. On Windows systems, the payload establishes persistence via scheduled tasks (T1053.005) and downloads secondary payloads (T1105). On Linux, cURL retrieves executables through the VPN tunnel. The trojanized version replaces WireGuard's standard Base64 decoding with a custom dynamically generated alphabet to evade analysis (T1027 - Obfuscated Files or Information). The actor demonstrates sophisticated OPSEC through domain impersonation (soprasteria-bg[.]com), use of SourceForge for malware distribution, and multi-platform payload delivery.

Targets & Patterns

The campaign specifically targets system administrators and IT professionals working in IT services and telecommunications sectors. Victims are selected based on resume analysis from job posting sites, indicating deliberate targeting of individuals with privileged access to corporate networks and infrastructure. The focus on IT personnel suggests an objective of gaining initial access to downstream client organizations through trusted third-party relationships. The use of Sopra Steria impersonation—a major international IT services firm—indicates targeting of mid-to-senior level IT staff who would find such job opportunities credible. Geographic focus includes Ukraine and potentially other regions where Sopra Steria operates. This targeting pattern aligns with Sandworm's historical focus on critical infrastructure and suggests potential supply-chain compromise objectives.

Historical Context

Sandworm (APT44) has an established history of targeting Ukrainian critical infrastructure and government entities, including previous destructive attacks. The Ukrainian CERT-UA attributes this activity to UAC-0145, assessed as a sub-cluster of Sandworm, indicating operational compartmentalization within the broader group. This campaign represents a tactical evolution from infrastructure-focused attacks to targeting IT personnel as initial access vectors, potentially enabling broader supply-chain compromise. The sophisticated social engineering and custom tooling development are consistent with Sandworm's known capabilities and resource investment in long-term operations.

Defensive Recommendations

  • Implement EDR solutions on all endpoints including personal devices used for corporate access, with continuous monitoring for scheduled task creation (T1053.005) and unusual PowerShell execution
  • Restrict VPN client installations to approved, cryptographically signed versions distributed through internal channels; block execution of unsigned or third-party VPN clients via application control policies
  • Monitor for non-standard WireGuard configuration parameters, particularly custom options like 'SymmetricKey', through configuration file inspection and network behavior analysis
  • Conduct security awareness training focused on recruitment-themed social engineering, emphasizing verification of recruiter identities through official company channels before downloading interview materials
  • Implement network egress filtering to detect and block cURL/PowerShell-based payload downloads (T1105) from VPN tunnels, particularly connections to SourceForge and newly registered domains mimicking legitimate IT firms

---

# Geopolitical Context

Geopolitical Context

The campaign attributed to UAC-0145, assessed to be a sub-cluster of Sandworm (APT44), represents a continuation of Russian-linked cyber operations targeting critical infrastructure enablers. Sandworm, historically associated with Russia's GRU military intelligence, has conducted high-impact operations against Ukrainian and international targets since at least 2015. This campaign's focus on IT professionals and system administrators—individuals with privileged access to enterprise networks—suggests an operational shift toward supply-chain positioning and credential harvesting that could enable follow-on intrusions into telecommunications and IT service providers. The use of elaborate social engineering, including live video interviews conducted in English and impersonation of a European IT firm (Sopra Steria), indicates a calculated effort to establish trust and expand targeting beyond Ukraine's borders. The campaign's timing, ongoing since May 2026, aligns with sustained Russian cyber activity amid broader geopolitical tensions.

State Actor Alignment

CERT-UA attributes the activity to UAC-0145, which it assesses to be linked to Sandworm (APT44). Sandworm is widely attributed by the cybersecurity community and Western governments to Russia's Main Intelligence Directorate (GRU), specifically Unit 74455. The group has been sanctioned by the United States, United Kingdom, and European Union for its role in disruptive cyber operations, including the 2015 and 2016 attacks on Ukraine's power grid, the NotPetya wiper attack in 2017, and interference operations targeting the 2018 Winter Olympics. The current campaign's attribution is consistent with Sandworm's established tradecraft, including sophisticated social engineering, custom malware development, and targeting of critical infrastructure sectors. The group's persistent focus on Ukraine, combined with targeting of IT service providers that may support clients across Europe and beyond, underscores its strategic role in Russian intelligence operations.

Business Impacty pro region

The campaign carries significant implications for European cybersecurity, particularly given the impersonation of Sopra Steria, a major European IT services firm with operations across the continent and government contracts in multiple EU member states. The targeting of IT professionals and system administrators creates potential for supply-chain compromise, whereby initial access to service providers could enable lateral movement into client networks spanning critical infrastructure, telecommunications, and government sectors. The use of English-language interviews and European corporate personas suggests the threat actor may be expanding its operational aperture beyond Ukraine to target IT professionals across Central and Eastern Europe, and potentially Western Europe. For NATO allies and EU member states, the campaign highlights persistent risks from Russian-linked threat actors seeking to pre-position access within networks that underpin digital infrastructure and government services. The incident also underscores the vulnerability of remote work practices and personal device usage, which may lack the security controls present in corporate environments.

Forecast

If the campaign continues without significant disruption, it is likely that Sandworm will refine its social engineering techniques and expand impersonation of additional European IT firms to broaden its target pool. Should the group successfully compromise IT service providers or telecommunications firms, follow-on activity may include credential theft, network reconnaissance, and pre-positioning for disruptive or espionage operations aligned with Russian strategic interests. If geopolitical tensions involving Russia escalate—particularly in relation to Ukraine or NATO—compromised IT infrastructure could be leveraged for destructive attacks similar to historical Sandworm operations such as NotPetya or power grid disruptions. Conversely, if Western cybersecurity agencies and private sector partners enhance information sharing on the campaign's indicators and tradecraft, detection rates may improve, forcing the threat actor to retool or shift tactics. Organizations in the IT services and telecommunications sectors should anticipate continued targeting and prioritize vetting of recruitment communications, particularly those involving VPN clients or remote access tools.