Plan
active
Sandworm UAC-0145 Uses Fake Recruiters to Deliver Backdoored VPN
- Engineer — Learn: Sandworm is delivering trojanized VPN clients through fake job-interview lures targeting IT professionals — a supply-chain-adjacent social engineering vector. No patch action exists, but teams should review policies on installing software provided during recruiting workflows and verify VPN client integrity via official sources only.
- SOC/IR — Plan: The campaign introduces a new Sandworm TTP: trojanized VPN with command-execution capability delivered via recruiter impersonation. No IOCs are currently available in this disclosure, but detection engineers should queue rules for unauthorized VPN client installs and anomalous outbound connections from VPN processes in anticipation of CERT-UA releasing indicators.
- Leader — Learn: Sandworm expanding its IT-targeting playbook to recruiter impersonation is notable trend intelligence, but absent evidence of Western-enterprise targeting or published IOCs, this does not require immediate leadership action; file for the next threat-landscape briefing.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.