Threat Intelligence

Fake Job Interviews Used to Trick IT Workers Into Installing Malicious VPN Software

The Hacker News · 12 Aug 2026
Key Takeaway Be wary of unsolicited job offers or recruiter messages that ask you to download software, and verify any such requests through official channels before installing anything.

Ukraine's Computer Emergency Response Team (CERT-UA) has uncovered a social engineering campaign linked to Russian nation-state hackers, targeting IT workers by impersonating recruiters. The group, tracked as UAC-0145 and believed to be a subgroup of the notorious Sandworm (APT44) team, approaches victims with fake job opportunities to convince them to install software disguised as a legitimate VPN application.

Once installed, the fake VPN tool gives attackers the ability to run commands on the victim's device, potentially granting deep access into an organisation's systems and networks. Because the attack relies on convincing personal outreach rather than technical exploits, it can bypass many traditional security defences that focus on network-level threats.

This campaign highlights a growing trend where attackers target IT professionals specifically, since these individuals often have elevated access and administrative privileges within their organisations. A successful compromise of an IT worker's device can therefore have outsized consequences for a business's overall security.

social engineering Sandworm malware VPN IT security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.