Threats

Russian Military Hackers Target Ukrainian IT Workers

August 10, 2026 20:08 · 10 min read
Russian Military Hackers Target Ukrainian IT Workers

Hackers linked to Russia's military intelligence unit are posing as recruiters to trick Ukrainian IT workers into installing malicious software, researchers have found. Ukraine's computer emergency response team, CERT-UA, said the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia's GRU military intelligence agency.

How the Attack Works

The operation mostly targets system administrators and other IT professionals. According to CERT-UA, the hackers search legitimate Ukrainian job sites for potential victims, review their resumes, and then contact them while posing as recruiters for an IT company.

In one case investigated by the agency, the attackers claimed to represent a recruitment company called Atlas Business Group and told a potential victim they were hiring for a project involving Sopra Steria Bulgaria, part of a legitimate international IT services company. After making initial contact through a job website's built-in chat, the purported recruiters moved the conversation to Telegram.

The Recruitment Process

There, a fake HR manager conducted an initial screening, asking ordinary questions about the candidate's preferred work arrangements and English-language skills. The candidate was then invited to a Zoom interview, which involved an English-speaking man who appeared to be between 30 and 35 years old.

The agency did not say whether the person appearing in the interview was a genuine participant in the operation or an AI-generated persona. As the recruitment process continued, the hackers emailed the candidate instructions for what they claimed was a technical interview.

According to the research, the victim was told to connect to a corporate network using WireGuard, a legitimate open-source VPN protocol and software, in order to complete test assignments. The sender's email address was crafted to resemble one belonging to a regional Sopra Steria office.

The Malicious VPN App

When candidates tried to connect using the provided files, they encountered errors. The supposed recruiter then told them to download a custom VPN app called SopraVPN, hosted on the software distribution platform SourceForge and linked from a website designed to look like the company's official site.

Installing SopraVPN was the critical step in compromising the victim's computer, CERT-UA said. The hackers created the application using legitimate WireGuard open-source code but modified it so that malicious commands could be covertly executed on a victim's device.

Some commands were encrypted and embedded in the VPN configuration files, making them harder to identify during a basic inspection. CERT-UA did not disclose how many people had been targeted or identify the hackers' ultimate objective.

Other Similar Attacks

Sandworm, also tracked by researchers as APT44 and Seashell Blizzard, has been active for more than a decade and has been blamed for some of Russia's most disruptive cyber operations, including attacks on Ukraine's electricity grid. The group is not alone in using fake recruitment campaigns as a way to gain access to targeted systems.

Western intelligence agencies have previously warned that Chinese intelligence officers have posed as recruiters and consultants on professional networking and job platforms to approach government, military, and other personnel with access to sensitive information. North Korean hackers have also repeatedly impersonated recruiters in campaigns designed to steal credentials and cryptocurrency or compromise employees at technology companies.

In other operations, North Korean IT workers have sought employment at foreign companies under false identities to generate revenue for Pyongyang.


Source: The Record

Source: The Record

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free