Russian Military Hackers Impersonate Recruiters to Target Ukrainian IT Professionals
Sandworm, a notorious Russian military hacking group, is employing a sophisticated social engineering scheme, posing as recruiters to lure Ukrainian IT workers into installing malware.

Russian military hackers, identified as the Sandworm group, are actively targeting Ukrainian IT professionals by impersonating recruiters in a sophisticated social engineering campaign. This operation, which has been ongoing since at least May, aims to compromise individuals within Ukraine's vital technology sector, according to warnings issued by CERT-UA, Ukraine's computer emergency response team. Sandworm is a well-known hacking unit associated with Russia's GRU military intelligence agency, notorious for its disruptive cyber operations.
The attackers meticulously search legitimate Ukrainian job websites for potential victims, reviewing their resumes before initiating contact. In one documented instance, the hackers posed as recruiters for Atlas Business Group, claiming to be hiring for a project involving Sopra Steria Bulgaria, a legitimate international IT services company. The initial contact was made through a job website's chat feature, with the conversation subsequently moving to Telegram.
On Telegram, a fake HR manager conducted an initial screening, asking standard questions about the candidate's work preferences and language skills. The process advanced to a purported Zoom interview, featuring an English-speaking individual. CERT-UA has not specified whether the person in the interview was a real operative or an AI-generated persona, leaving open the possibility of advanced deception tactics.
As the recruitment process progressed, the hackers sent an email to the candidate with instructions for a technical interview, which required connecting to a corporate network via WireGuard, a legitimate open-source VPN protocol. The email address used was designed to closely mimic that of a Sopra Steria regional office, further enhancing the credibility of the phishing attempt.
When candidates attempted to use the provided files to connect, they encountered errors. The supposed recruiter then instructed them to download a custom VPN application named SopraVPN. This application was hosted on the software distribution platform SourceForge and linked from a website meticulously crafted to resemble the official Sopra Steria site.
The installation of SopraVPN was the critical step in compromising the victim's computer. CERT-UA revealed that the hackers had built the application using legitimate WireGuard open-source code but modified it to covertly execute malicious commands on the victim's device. Some of these commands were encrypted and embedded within the VPN configuration files, making them significantly harder to detect during routine security inspections.
While CERT-UA has not disclosed the exact number of individuals targeted or the ultimate objectives of the hackers, the Telegram account used by the fake recruiter was still accessible at the time of reporting, though the associated job advertisement had been removed. Sandworm, also tracked as APT44 and Seashell Blizzard, has a long history of sophisticated and impactful cyberattacks, including previous disruptions of Ukraine's power grid.
This tactic of using fake recruitment campaigns is not unique to Sandworm. Intelligence agencies have previously warned about similar methods employed by Chinese and North Korean hackers, who also pose as recruiters on professional networking sites to gain access to sensitive information or steal credentials and cryptocurrency. The ongoing campaign highlights the persistent threat posed by state-sponsored actors leveraging social engineering to infiltrate critical sectors.