Fake Job Interviews Used to Trick IT Workers Into Installing Malicious VPN Software
Ukraine's Computer Emergency Response Team (CERT-UA) has uncovered a social engineering campaign linked to Russian nation-state hackers, targeting IT workers by impersonating recruiters. The group, tracked as UAC-0145 and believed to be a subgroup of the notorious Sandworm (APT44) team, approaches victims with fake job opportunities to convince them to install software disguised as a legitimate VPN application.
Once installed, the fake VPN tool gives attackers the ability to run commands on the victim's device, potentially granting deep access into an organisation's systems and networks. Because the attack relies on convincing personal outreach rather than technical exploits, it can bypass many traditional security defences that focus on network-level threats.
This campaign highlights a growing trend where attackers target IT professionals specifically, since these individuals often have elevated access and administrative privileges within their organisations. A successful compromise of an IT worker's device can therefore have outsized consequences for a business's overall security.