Russian Sandworm Hackers Lure IT Admins With Fake Job Offers, Poisoned VPN Software
Security researchers say the Sandworm hacking group, widely linked to Russian military intelligence, has spent the past several months running a targeted campaign against system administrators and other IT professionals. The attack starts simply enough: a message posing as a job recruiter, often sent through professional networking channels, that eventually steers the target toward downloading what looks like a legitimate VPN tool.
Instead of the real thing, victims get a modified build of the open-source WireGuard client that has been quietly stitched with malicious code. Because WireGuard is trusted and widely deployed by network administrators, a tampered version can slip past casual scrutiny and hand attackers a foothold on machines that typically have elevated access to internal networks and infrastructure.
The campaign has reportedly been active since at least May, suggesting a sustained effort rather than a one-off phishing blast. Sandworm has a long history of targeting critical infrastructure and enterprise networks, and going after the people who manage VPNs, firewalls, and servers directly is a logical shortcut to broader network compromise.