GKRootWire
AI xAI Publishes Details on Its Grok Web CrawlerAI Why 'Human-in-the-Loop' Might Have It BackwardsDev Tools Modular Ships Mojo 1.0, Marking the Language's Production DebutAI OpenAI's Head of Ethics Exits Less Than a Year Into the JobAI Researchers Show How to Extract Hidden Reasoning from Proprietary LLM APIsAI Nvidia Debuts Nemotron 3.5 Lightning and NeMo Switchyard for Local AI WorkflowsAI xAI Publishes Details on Its Grok Web CrawlerAI Why 'Human-in-the-Loop' Might Have It BackwardsDev Tools Modular Ships Mojo 1.0, Marking the Language's Production DebutAI OpenAI's Head of Ethics Exits Less Than a Year Into the JobAI Researchers Show How to Extract Hidden Reasoning from Proprietary LLM APIsAI Nvidia Debuts Nemotron 3.5 Lightning and NeMo Switchyard for Local AI Workflows
Security

Russian Sandworm Hackers Lure IT Admins With Fake Job Offers, Poisoned VPN Software

The state-linked group is reportedly baiting sysadmins with recruiter messages that deliver a backdoored version of the WireGuard VPN client.

Security researchers say the Sandworm hacking group, widely linked to Russian military intelligence, has spent the past several months running a targeted campaign against system administrators and other IT professionals. The attack starts simply enough: a message posing as a job recruiter, often sent through professional networking channels, that eventually steers the target toward downloading what looks like a legitimate VPN tool.

Instead of the real thing, victims get a modified build of the open-source WireGuard client that has been quietly stitched with malicious code. Because WireGuard is trusted and widely deployed by network administrators, a tampered version can slip past casual scrutiny and hand attackers a foothold on machines that typically have elevated access to internal networks and infrastructure.

The campaign has reportedly been active since at least May, suggesting a sustained effort rather than a one-off phishing blast. Sandworm has a long history of targeting critical infrastructure and enterprise networks, and going after the people who manage VPNs, firewalls, and servers directly is a logical shortcut to broader network compromise.

Why it matters: IT and network admins are high-value targets because compromising their machines often means inheriting the keys to an entire organization's infrastructure. Trojanizing a trusted, open-source tool like WireGuard is a reminder to verify software checksums and download only from official sources, even when a job pitch makes the request feel routine.

Sources: BleepingComputer