State-Sponsored Hacking Group Sandworm Targets Job Seekers with Malicious VPN Software
Cyber espionage actors are leveraging the trust and eagerness of job seekers in a highly targeted malware campaign. Security researchers have identified an advanced intrusion set that lures prospective candidates on professional job-search platforms into downloading a malicious "corporate VPN test." Once executed on a Windows machine, the program covertly establishes a scheduled task to maintain persistence and downloads secondary malware payloads.
The activity, which has been observed since at least May 2026, has been attributed to a threat cluster designated as UAC-0145. This cluster encompasses UAC-0002, a highly notorious threat group widely tracked by cybersecurity agencies and private firms under several aliases, including Sandworm, APT44, and Seashell Blizzard. Historically linked to state-sponsored intelligence operations, this group has a long-standing reputation for conducting aggressive espionage and disruptive cyber campaigns globally.
According to reports originally published by GBHackers, the attack chain begins with direct engagement on mainstream job-search platforms. Threat actors pose as employers or recruiters, reviewing candidate profiles and initiating contact with potential targets. Under the guise of a pre-employment technical assessment or a requirement to connect to a corporate staging environment, the attackers instruct the victim to download and run the simulated VPN testing software.
Once the unsuspecting candidate runs the fake utility on a Windows operating system, the software silently configures a scheduled task. In the cybersecurity landscape, scheduled tasks are a common mechanism used by advanced persistent threats (APTs) to ensure their malicious code executes automatically, even after the system is restarted. This persistent foothold is then utilized to pull down additional malware from attacker-controlled servers, potentially giving the threat actors full control over the compromised endpoint.
This campaign underscores a growing trend where sophisticated state-sponsored actors rely heavily on social engineering rather than complex software exploits to breach networks. By targeting individuals during the job application process, attackers exploit the inherent compliance typical of candidates eager to secure employment. Security experts warn that such campaigns pose a significant risk, as compromised personal devices of job seekers can easily serve as a gateway to breach corporate networks once those individuals secure employment and connect to organizational infrastructure.
Comments (0)
Be the first to comment.
Join the discussion