CuraSec

Act active

Sandworm targets IT pros with trojanized WireGuard via fake job offers

2026-08-12 11:57 UTC · BleepingComputer · read the source ↗ #apt#supply-chain#social-engineering
  • Engineer — Plan: Sandworm is delivering trojanized WireGuard VPN installers through fake recruitment outreach targeting sysadmins — people with elevated access like yours are the intended victims. Verify all VPN client installs trace to official sources, and alert IT staff to treat unsolicited job offers that include software downloads as high-risk.
  • SOC/IR — Act: An active Sandworm campaign has been running since at least May against high-privilege IT users using trojanized VPN software as the payload delivery mechanism. Hunt for anomalous WireGuard process behavior and unexpected software installations by IT/admin accounts; map activity to T1195/T1566 and extend your Sandworm TTP coverage in your SIEM from May onward.
  • Leader — Plan: Russian GRU-linked Sandworm is specifically targeting sysadmins and IT professionals — the people with the highest internal access — via fake job offers this quarter. Brief IT leadership on the campaign and confirm your acceptable-use policies cover software install restrictions and vetting of recruitment-related communications.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.