THREATOPS
THREAT OPSThreat News › Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

medthehackernewsPublished 2026-08-11

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware.

CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,

Attributed threat actors

MITRE ATT&CK techniques

Original source: https://thehackernews.com/2026/08/sandworm-linked-uac-0145-uses-fake-job.html