bleeping-computer · Crawled Aug 11, 2026

Sandworm hackers target IT pros with trojanized WireGuard VPN client

2 IoCs 1 Actors
Read original article ↗

AI Summary

The Russian threat group Sandworm, operating as UAC-0145, has been targeting IT professionals and system administrators since at least May 2026 through a social engineering campaign involving fake job offers. The attackers pose as legitimate IT companies, such as Sopra Steria, and lure victims into downloading a trojanized WireGuard-based client called 'SopraVPN' from SourceForge. The malicious client contains a custom Base64 decoder and executes PowerShell code that establishes persistence via scheduled tasks on Windows or downloads additional payloads on Linux through attacker-controlled infrastructure.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 2 extracted

Type Value Detail
Domain soprasteria-bg[.]com Details →
GitHub Repo https://sourceforge.net/projects/sopravpn/ Details →

MITRE ATT&CK TTPs 25 techniques