Fake Job Offers From Russian Hackers Target Ukrainian IT Staff
Ukraine's cyber emergency team says a Sandworm subgroup is posing as recruiters to slip remote-control malware onto engineers' laptops.

Key points
- Ukraine's Computer Emergency Response Team (CERT-UA) has linked a new fake-recruiter campaign to a Russian hacking subgroup it calls UAC-0145.
- UAC-0145 sits inside Sandworm, the Russian military intelligence hacking unit also known as APT44.
- Hackers approached Ukrainian IT workers with bogus job offers, then pushed them to install a booby-trapped VPN app.
- The app secretly gives attackers command execution on the victim's machine, handing them a foothold inside Ukrainian tech companies.
Ukraine's national cyber defenders have gone public with a fresh Russian espionage campaign, and anyone in tech will recognise the target list. They're chasing IT workers, using fake job interviews as bait.
The Computer Emergency Response Team of Ukraine attributes the activity to a cluster it labels UAC-0145, a subgroup of Sandworm, the offensive unit run out of Russia's military intelligence service, the GRU. Sandworm is the same operation Western agencies have blamed for attacks on Ukraine's power grid and for NotPetya, malicious software that posed as ransomware but was built to destroy data. We first covered UAC-0145 on 19 July, when the same subgroup used fake CAPTCHA prompts to plant data-stealing malware.
How did the attack work?
Hackers posed as recruiters and contacted Ukrainian IT staff with what looked like a normal job opportunity. At some point in the interview process, the target was asked to install what they were told was a corporate VPN client, software that normally builds a secure tunnel between a laptop and a company network.
That VPN was the trap. The installer sets up a working VPN connection so nothing looks wrong, but it also quietly gives the attacker command execution on the victim's computer. CERT-UA traced the malicious tooling back to Sandworm-linked infrastructure.
Once that foothold is in place, attackers can steal credentials, pivot into the employer's network, or plant persistent malware.
Why go after IT workers?
Engineers are a shortcut to everything else. An IT worker's laptop typically has cloud console access, source code, deployment keys and production secrets that would take weeks to phish from a regular office employee.
Get one platform engineer and you often get the keys to the production environment. The failure mode is depressingly familiar: a developer installs a random binary on their work machine because a recruiter asked, and no endpoint tool blocks it because the file is freshly signed and not yet on any block list. IAM audits catch this eventually. Eventually is too late.
Should you worry?
If you work in tech in Ukraine, or anywhere nearby, treat unsolicited recruiter messages the way you'd treat a cold email claiming to be your bank. Don't install software as part of an interview. No legitimate employer needs you running their VPN client before you've signed anything.
For everyone else, the practical read is straightforward. Russian state hackers remain focused on Ukraine and they're getting more creative about who they target.
| Detail | What CERT-UA says |
|---|---|
| Cluster name | UAC-0145 |
| Parent group | Sandworm / APT44 (Russian GRU) |
| Target | IT workers in Ukraine |
| Lure | Fake recruiter contact, job interview |
| Payload | Trojanised VPN client with command execution |
The post-mortem on any of these incidents will say the perimeter was a recruiter DM.
Operational takeaway: treat any binary handed to a developer during a hiring process as untrusted code, because that's exactly what it is.



