The UAC-0145 group uses fake interviews to target system administrators and other IT workers in Ukraine. The campaign, attributed to Sandworm, leads victims to install a malicious VPN and ultimately have their device fully compromised.

The warning comes from the Ukrainian cyber incident response team CERT-UA, which says the activity has been ongoing since at least May 2026. The announcement was published on August 10 and primarily targets tech professionals looking for work.
See also: CERT-UA: Sandworm turns to ClickFix attacks
UAC-0145's fake interviews targeting IT workers
Attackers search for candidates on job search platforms and study their CVs before contacting them. They present themselves as representatives of IT companies, including ATLAS Business Group, and initiate the conversation through the platform or via Telegram.
The conversation then moves to a Zoom conference call. The supposed recruiter discusses the position and the candidate’s English level, creating a persuasive environment before asking for participation in a technical assessment.
The instructions for the assessment are sent via email, with the sender’s addresses mimicking regional offices of the legitimate company Sopra Steria. The email includes configuration files for a WireGuard connection and a link to a new meeting where the test is supposed to be attended.

Malicious VPN bypasses user trust
When the connection to the original files fails, the attackers suggest SopraVPN, a modified client available through projects on SourceForge and appearing as a Sopra Steria solution. The official CERT-UA analysis describes the tool as the point of full compromise of the device.
SopraVPN is based on the WireGuard source code, but has been modified with the SymmetricKey. It stores, in Base64 encoding, data for AES-256-GCM decryption. The key is derived from the PrivateKey and exposes PowerShell code.
The code is executed via a WireGuard mechanism associated with the PostUp option. On Windows, it can create a scheduled task to download the next file, while on Linux, it uses cURL to download an executable file from a remote infrastructure. The exact nature of the next payload is unknown.
See also: Windows Hello for Business: Malware for persistent access to Entra ID
How to limit the risk
CERT-UA recommends that IT professionals be wary of job offers that request the installation of unknown software or the use of configuration files from unverified sources. The identity of the company and the person responsible should be confirmed by an independent channel.
For organizations, the SecNews technical team recommends accessing corporate resources only from managed devices, with active protection software and strict policies. Constant monitoring of new VPNs, scheduled tasks and outbound connections can reduce response time.
HR teams can also inform candidates that no technical tests require VPN installation outside of the formal process. A clear policy reduces the pressure of urgency and gives employees time to check the sender, link, and origin of each file.
See also: Strong ransomware hit in Sithonia, Halkidiki
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The choice of professionals with access to infrastructure makes the campaign particularly risky. The fake interviews do not simply act as bait, but as a carefully planned stage before the tool is installed. A system administrator may have rights to servers, corporate networks, or remote access services, so a breach of a personal computer can become an incident for the entire organization.
The case also highlights the importance of independent verification. The use of well-known names, professional profiles, and real video conferencing tools does not prove that the interlocutor is genuine. Candidates should seek the offer from the company's official website and avoid software that is recommended exclusively through chat.
No specific hashes or full description of the next payload have been released yet. That doesn't diminish the risk: organizations can look for new VPN installations, unknown scheduled tasks, and unusual outbound connections, combining the findings with device logs.

Countering fake interviews requires the same caution as any other form of social engineering. The case shows that a recruitment process can be turned into an initial entry point without the victim opening an attachment. The combined use of impersonation, video conferencing, and a malicious VPN increases the credibility of the trap, so verification of each tool should precede installation.
