Search/soprasteria-bg.com
IOC

soprasteria-bg.com

Type
DOMAIN
Source
News extraction
First seen
Aug 11, 2026
Last seen
Aug 11, 2026
Look up on VirusTotal
Connections
2 relationships
Sandworm hackers target IT pros with trojanized WireGuard VPN client
Hackers associated with the Russian threat group Sandworm have been targeting system administrators and IT professionals through fake job offers since at least May. A report from the Ukrainian Computer Emergency Response Team (CERT) details a social engineering campaign attributed to UAC-0145, which is believed to be a sub-cluster of Sandworm (APT44). In the campaign, the threat actor targets victims while posing as IT companies and recruiters. The agency says that the attacker studies the targets' resumes uploaded on job sites and then initiates direct contact. Conversations are then moved to Telegram to arrange a video interview over Zoom. During the interview, which is conducted in English, the candidates receive mock technical assignments that require them to connect to a corporate VPN. In one case that CERT-UA observed, the attacker impersonated the international IT firm Sopra Steria using seemingly legitimate email addresses similar to the company’s office in Bulgaria. “In parallel, additional instructions for the technical interview are sent via email, including configuration files for connecting to a 'corporate' VPN using Wireguard (Linux/Windows) to supposedly perform test tasks,” CERT-UA says. The downloaded file is configured to produce a fake error. The attackers then prompt the victim to download a modified WireGuard-based client called “SopraVPN” from SourceForge. The SourceForge page even includes a link to soprasteria-bg[.]com to increase credibility, although the domain has no connection to the legitimate company. The trojanized client supports a malicious, nonstandard “SymmetricKey” configuration option that decrypts and executes embedded PowerShell code. On Windows, the malicious command creates a scheduled task and downloads an additional payload from the Internet. On Linux, it uses cURL to retrieve another executable from attacker-controlled infrastructure through the VPN. CERT-UA also noted that WireGuard’s standard Base64 decoding was replaced in the trojanized version with a custom, dynamically generated Base64 alphabet, which renders key strings unreadable with standard decoders and protects the PowerShell code from analysis. The Ukrainian cyber agency advises telecommunications providers and IT companies whose staff are targeted by this campaign to restrict corporate resource access to managed, continuously monitored devices protected by EDR, including when employees use personal equipment. APT44 is notorious for targeting critical infrastructure and government entities both in Ukraine, and also in other countries. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 11, 2026extracted
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44, Seashell Blizzard, and UAC-0002), a sophisticated hacking group affiliated with the GRU. The campaign is assessed to be ongoing since May 2026. "Specifically, on job search websites, after reviewing a candidate's resume, the attackers contact a potential victim – typically a system administrator or IT specialist – on behalf of an IT company (such as ATLAS Business Group)," CERT-UA said. Although initial communications take place via built-in online chat, the conversation subsequently shifts to messaging apps like Telegram, where a preliminary chat takes place with a purported HR manager who claims to be in charge of the candidate screening process for Sopra Steria Bulgaria, a legitimate Europe-based consulting and software development company. As part of the chat, the agency said general work-related questions and the candidates' English language proficiency are discussed, after which they are invited to join a Zoom videoconference call. While the meeting does take place as expected with an English-speaking man who appears to be between 30 and 35 years old, it's unclear whether the person showing up in the interview was a genuine participant or a synthetic persona generated using artificial intelligence (AI). In tandem, additional instructions for a technical interview are sent via an email. This includes configuration files for connecting to the corporate VPN using WireGuard to supposedly complete an assessment, along with a link to a second Zoom meeting during which the test is monitored. Should the victim attempt to connect to the VPN using the provided configuration files, they run into error messages, causing the threat actors to recommend downloading a custom VPN solution named SopraVPN hosted on SourceForge by sharing a bogus link designed to mimic Sopra Steria Bulgaria's website ("soprasteria-bg[.]com") - sourceforge[.]net/projects/soprabulgariavpn sourceforge[.]net/projects/sopravpn The Hacker News also identified a third SourceForge project called "sourceforge[.]net/projects/soprasteriavpn," which claims to be an "open-source corporate VPN solution designed for businesses seeking secure remote access and site-to-site connectivity without expensive licensing fees," according to cached Google Search results. None of these projects are available for download. "The essence of this trick is that the attackers' VPN client was compiled from the WireGuard source code with a number of modifications," CERT-UA explained. "Specifically, support for the non-standard 'SymmetricKey' option has been added to the configuration processing mechanism; its value contains BASE64-encoded data for AES-256-GCM: a nonce, ciphertext, and an authentication tag." "A 32-byte value obtained by decoding 'PrivateKey' is used as the AES-256 key. The PowerShell code decrypted in this way is then passed to the standard 'runScriptCommand' mechanism, which WireGuard uses, in particular, to execute commands specified by the 'PostUp' option." Put differently, the poisoned version of WireGuard allows an attacker to run arbitrary commands on the victim host without their knowledge. The Windows VPN client also makes use of a PowerShell command to create a scheduled task that downloads a secondary payload from a remote URL, while the Linux variant uses cURL to download the executable file from the attackers' infrastructure via a VPN. The exact nature of the next-stage payload is unclear. CERT-UA is urging IT professionals to be on the lookout for social engineering techniques to stay protected against potential malware attacks. Organizations are recommended to allow access to corporate resources only from managed devices on which appropriate security software is installed and ensure relevant policies are configured and continuous monitoring is enforced. The disclosure comes less than a month after the agency attributed the threat actor to another campaign that employs the ClickFix social engineering tactic to infect Ukrainian machines with data-stealing malware. With the latest development, Russian threat actors have joined alongside Chinese, Iranian, and North Korean adversaries in using fake recruitment campaigns to gain unauthorized access to targeted systems.
thehackernews.comAug 11, 2026extracted