Trojanized WireGuard VPN to Infect IT Professionals

Overview

Cybersecurity analysts at CERT‑UA have uncovered a new Sandworm campaign (UAC‑0145, also known as APT44/Seashell Blizzard) that weaponizes fake job interviews to compromise IT professionals. By impersonating recruiters, conducting live video calls, and delivering a Trojanized WireGuard VPN client, attackers aim to infiltrate networks managed by system administrators and IT specialists.

Attack Flow

  • Recruiter impersonation: Attackers pose as IT employers, initiating chats via job sites and Telegram.
  • Staged interviews: Candidates undergo basic screenings and Zoom calls with seemingly real interviewers.
  • Technical assessment trap: Victims receive WireGuard configuration files framed as test tasks.
  • Trojanized SopraVPN client: When the connection fails, candidates are directed to download SopraVPN—a modified WireGuard build containing malicious code.

Technical Details

  • Windows variant: Decrypts embedded PowerShell code via a hidden SymmetricKey parameter, creating scheduled tasks and fetching payloads online.
  • Linux variant: Uses curl to retrieve executables from attacker infrastructure, with DNS servers provided in the VPN configuration.
  • Persistence: Modified Base64 decoding and scheduled tasks ensure continued compromise.
  • IoCs:
    • Malicious files: sopravpn_v7__1_.exe, sopraconf.conf, sopraconfLinux.conf.
    • Domains: douncloud[.]site, atlasgroup-ua[.]com, soprasteria-bg[.]com.
    • IP: 139.28.36[.]23.
    • Telegram: @Sales_ManagerABG.

Why It Matters

This campaign is notable for its social engineering sophistication:

  • Familiar hiring steps lower suspicion.
  • IT professionals are prime targets due to their privileged access to credentials, servers, and VPNs.
  • A single compromised administrator device can enable network probing, credential theft, and data exfiltration.

Defensive Guidance

  • Verify employers independently: Use official channels before installing software.
  • Block untrusted VPN clients: Only allow managed devices with endpoint protection.
  • Isolate interview tasks: Never run code or VPN configs on production machines.
  • Monitor suspicious activity: Review scheduled tasks, PowerShell logs, and new VPN configurations.
  • Establish reporting processes: Encourage staff to report suspicious recruitment contacts promptly.

Expert in the Cloud Insight

Sandworm’s fake job interview campaign demonstrates how attackers exploit trust and urgency in recruitment processes to bypass technical suspicion. By Trojanizing a legitimate VPN client, they weaponize routine IT workflows. For defenders, the lesson is clear: security awareness must extend beyond phishing emails to include recruitment fraud, where social engineering meets technical compromise.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.