Utopia Tech
SecurityAI-assisted1 min read

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

CERT-UA has identified a social engineering campaign by UAC-0145, a subgroup of Russian state-sponsored threat actor Sandworm, targeting Ukrainian IT workers. The attackers pose as recruiters conducting fake job interviews to deceive victims into installing malicious VPN software capable of executing remote commands.

UT

Utopia Tech

August 11, 2026 · 1 min read

Share

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content