Actor Profile
UAC-0145 is a threat cluster operating as a subgroup within Sandworm (also tracked as APT44, Seashell Blizzard, UAC-0002, ELECTRUM, Telebots, IRON VIKING), a sophisticated nation-state hacking group affiliated with Russia's GRU military intelligence. The actor leverages social engineering tactics to compromise Ukrainian IT infrastructure, demonstrating operational continuity with Sandworm's broader strategic objectives against Ukrainian targets. This subgroup specializes in recruitment-themed social engineering campaigns designed to establish initial access to IT environments through trusted professional channels.
TTPs (Tactics, Techniques, Procedures)
Initial access via social engineering on job search platforms, impersonating legitimate IT companies (Sopra Steria Bulgaria, ATLAS Business Group). Shifts communications to Telegram for OPSEC. Conducts fake Zoom videoconference interviews, potentially using AI-generated personas. Delivers trojanized WireGuard VPN client via SourceForge and typosquatted domains (soprasteria-bg[.]com). Modified VPN client supports non-standard 'SymmetricKey' configuration option for AES-256-GCM encrypted PowerShell execution via 'PostUp' mechanism (T1059.001). Establishes persistence through scheduled tasks on Windows (T1053.005). Downloads secondary payloads via PowerShell (Windows) and cURL (Linux) through VPN tunnel (T1090). Sandworm is known to employ T1203 (Exploitation for Client Execution), T1041 (Exfiltration Over C2), T1040 (Network Sniffing), T1027.010 (Obfuscation), and T1132.001 (Standard Encoding) among other techniques.
Targets & Patterns
Campaign specifically targets Ukrainian IT workers, particularly system administrators and IT specialists, since May 2026. Victims are identified through job search websites where resumes are reviewed. The targeting of IT personnel represents a strategic approach to gain privileged access to corporate networks and critical infrastructure. This aligns with Sandworm's historical focus on Ukrainian entities across multiple sectors, particularly during ongoing geopolitical conflict. The use of recruitment lures exploits the trust inherent in professional hiring processes and targets individuals with elevated network access and technical knowledge, enabling lateral movement and deeper network compromise.
Historical Context
UAC-0145 was previously attributed by CERT-UA to a campaign employing ClickFix social engineering tactics to distribute data-stealing malware against Ukrainian targets less than a month prior to this disclosure. Sandworm (G0034) has a well-documented history of destructive operations against Ukraine, including deployment of Bad Rabbit, GreyEnergy, Prestige ransomware, AcidPour, and the NotPetya wiper. The group is also linked to VPNFilter router malware and Cyclops Blink campaigns. This fake recruitment campaign represents a tactical evolution, aligning UAC-0145 with broader trends observed across nation-state actors including Chinese, Iranian, and North Korean groups who similarly leverage recruitment-themed social engineering for initial access.
Defensive Recommendations
- Monitor for non-standard WireGuard VPN client installations, particularly those downloaded from SourceForge or unofficial domains; validate VPN software against known-good hashes from official sources
- Detect T1059.001 PowerShell execution via Sysmon Event ID 1 and 4104 (script block logging); alert on PowerShell spawned by VPN client processes or containing Base64-encoded AES decryption routines
- Implement application control policies to block execution of unsigned or untrusted VPN clients; restrict scheduled task creation (T1053.005) to authorized administrative accounts with EDR monitoring
- Enforce security awareness training focused on recruitment-themed social engineering, including verification of recruiter identities through official company channels and scrutiny of interview processes requiring custom software installation
- Restrict corporate resource access to managed devices with endpoint detection and response (EDR) solutions; monitor for outbound connections to VPN tunnels from non-standard clients and unusual cURL/PowerShell download activity
---
# Geopolitical Context
Geopolitical Context
The campaign, attributed by CERT-UA to UAC-0145—a subgroup within Sandworm (APT44)—represents a continuation of Russian intelligence operations against Ukraine's critical IT workforce. Sandworm, linked to Russia's GRU military intelligence directorate, has maintained persistent cyber operations against Ukrainian infrastructure since at least 2015. This social engineering effort, active since May 2026, demonstrates tactical evolution: rather than exploiting software vulnerabilities, the operation targets the human element by impersonating legitimate European IT firms (Sopra Steria Bulgaria) to compromise system administrators and IT specialists. The use of sophisticated tradecraft—including live video interviews, possibly AI-generated personas, and custom-modified open-source VPN software—indicates sustained investment in operational security and psychological manipulation. The campaign aligns with broader Russian strategic objectives to degrade Ukrainian resilience by penetrating IT supply chains and gaining persistent access to enterprise networks.
State Actor Alignment
CERT-UA attributes the activity to UAC-0145, assessed as a subgroup of Sandworm (also tracked as APT44, Seashell Blizzard, and UAC-0002). Sandworm is publicly linked to Unit 74455 of Russia's Main Intelligence Directorate (GRU). The group has been subject to U.S. indictments and international sanctions for prior destructive cyber operations, including NotPetya (2017) and attacks on Ukrainian critical infrastructure. This campaign's targeting of Ukrainian IT personnel is consistent with Russia's documented pattern of cyber operations supporting its ongoing military conflict with Ukraine. The operation joins a broader trend of state-aligned actors—including Chinese, Iranian, and North Korean groups—employing fake recruitment lures for intelligence collection and network access.
Business Impacty pro region
For Ukraine, the campaign underscores persistent threats to its IT sector, which is critical both for domestic resilience and as a growing export industry. Compromise of system administrators could enable lateral movement into government, defense, and private-sector networks. For the European Union, the impersonation of Sopra Steria Bulgaria—a legitimate EU-based consulting firm—may erode trust in cross-border recruitment and remote work practices, particularly affecting IT labor markets in Central and Eastern Europe. The use of widely available platforms (SourceForge, Telegram, Zoom) complicates attribution and takedown efforts, highlighting gaps in platform governance. Globally, the campaign illustrates the convergence of social engineering with open-source software supply chain risks: the weaponization of WireGuard, a trusted VPN tool, may prompt security reviews of other open-source networking software used in enterprise environments.
Forecast
If UAC-0145 maintains operational tempo, additional Ukrainian IT professionals and adjacent sectors (telecommunications, managed service providers) are likely to be targeted through similar recruitment-themed lures in the coming months. If the modified WireGuard tooling proves effective, it may be adopted by other GRU-affiliated clusters or shared within Russian intelligence ecosystems, potentially expanding geographic scope beyond Ukraine. Should European authorities or platform providers take enforcement action—such as domain takedowns or SourceForge project removals—the group is likely to migrate to alternative hosting infrastructure and refine impersonation techniques. If awareness campaigns by CERT-UA and industry partners succeed in educating IT workers, the operational success rate of this campaign may decline, prompting a shift toward alternative initial access vectors such as supply chain compromise or credential harvesting. Organizations employing remote hiring practices should anticipate continued exploitation of recruitment workflows as an attack surface.
