Fake Job Offers From Russian Hackers Target Ukrainian IT Staff

Ukraine's cyber emergency team says a Sandworm subgroup is posing as recruiters to slip remote-control malware onto engineers' laptops.

ThreatVectr Newsdesk· 3 min read
Full-frame 16:9 photoreal editorial shot of a laptop screen in a dim office, showing a generic fake verification prompt with a highlighted keyboard shortcut ins
Share

Key points

  • Ukraine's Computer Emergency Response Team (CERT-UA) has linked a new fake-recruiter campaign to a Russian hacking subgroup it calls UAC-0145.
  • UAC-0145 sits inside Sandworm, the Russian military intelligence hacking unit also known as APT44.
  • The hackers approached Ukrainian IT workers with bogus job offers, then pushed them to install a booby-trapped VPN app.
  • The app secretly lets attackers run commands on the victim's machine, giving them a foothold inside Ukrainian tech companies.

Ukraine's national cyber defenders have gone public with a fresh Russian espionage campaign, and the target list will feel uncomfortably familiar to anyone in tech. The hackers are chasing IT workers themselves, using fake job interviews as bait.

The Computer Emergency Response Team of Ukraine, known as CERT-UA, attributes the activity to a cluster it labels UAC-0145. That cluster is a subgroup of Sandworm, the long-running offensive unit run out of Russia's military intelligence service, the GRU. Sandworm is the same operation Western agencies have blamed for attacks on Ukraine's power grid and for the NotPetya wiper, malicious software that pretended to be ransomware but was really built to destroy data.

How did the attack work?

The hackers posed as recruiters and reached out to Ukrainian IT staff with what looked like a normal job opportunity. Somewhere in the interview process, the target was asked to install what they were told was a corporate VPN client, software that normally builds a secure tunnel between a laptop and a company network.

That VPN was the trap. In practice, the installer sets up a working VPN connection so nothing looks off, but it also quietly gives the attacker the ability to run commands on the victim's computer. First reported by The Hacker News, the campaign was flagged after CERT-UA traced the malicious tooling back to Sandworm-linked infrastructure.

Once that foothold is in place, the attackers can do the usual things: steal credentials, pivot into the employer's network, plant more malware, or just sit and watch.

Why go after IT workers?

Engineers are a shortcut to everything else. An IT worker's laptop typically has cloud console access, source code, VPN certificates, and secrets that would take weeks to phish out of a normal office employee.

Get one platform engineer, and you often get the keys to the production environment. The failure mode here is depressingly common: a developer or SRE installs a random binary on their work machine because a recruiter asked them to, and no endpoint tool blocks it because the file is freshly signed and not yet on any block list.

What should ordinary readers take from this?

If you work in tech in Ukraine, or frankly anywhere in the region, treat unsolicited recruiter messages with the same suspicion you would treat a cold email from your bank. Do not install software as part of an interview. No legitimate employer needs you to run their VPN client before you have signed a contract.

For everyone else, the practical read is simpler. Russian state hackers are still very much focused on Ukraine, and they are getting more creative about who they target and how.

Detail What CERT-UA says
Cluster name UAC-0145
Parent group Sandworm / APT44 (Russian GRU)
Target IT workers in Ukraine
Lure Fake recruiter contact, job interview
Payload Trojanised VPN client with command execution

One thing the post-mortem will say: the perimeter was a Slack DM from someone claiming to hire.

Operational takeaway: treat any binary handed to a developer during a hiring process as untrusted code, because that is exactly what it is.

© 2026 Threat Vectr