<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sandworm on CuraSec</title><link>https://curasec.metacog.co.kr/tags/sandworm/</link><description>Recent content in Sandworm on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 12 Aug 2026 11:57:00 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/sandworm/index.xml" rel="self" type="application/rss+xml"/><item><title>Sandworm UAC-0145 Uses Fake Recruiters to Deliver Backdoored VPN</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-sandworm-linked-uac-0145-uses-fake-job-interviews-to-push-vp/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-sandworm-linked-uac-0145-uses-fake-job-interviews-to-push-vp/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Sandworm is delivering trojanized VPN clients through fake job-interview lures targeting IT professionals — a supply-chain-adjacent social engineering vector. No patch action exists, but teams should review policies on installing software provided during recruiting workflows and verify VPN client integrity via official sources only.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The campaign introduces a new Sandworm TTP: trojanized VPN with command-execution capability delivered via recruiter impersonation. No IOCs are currently available in this disclosure, but detection engineers should queue rules for unauthorized VPN client installs and anomalous outbound connections from VPN processes in anticipation of CERT-UA releasing indicators.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Sandworm expanding its IT-targeting playbook to recruiter impersonation is notable trend intelligence, but absent evidence of Western-enterprise targeting or published IOCs, this does not require immediate leadership action; file for the next threat-landscape briefing.&lt;/li>
&lt;/ul></description></item><item><title>CrowdStrike: Detecting SANDWORM_MODE AI Toolchain Supply Chain Attacks</title><link>https://curasec.metacog.co.kr/insights/2026-07-22-denying-the-worm-detecting-sandworm-mode-and-the-emerging-cl/</link><pubDate>Wed, 22 Jul 2026 12:46:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-22-denying-the-worm-detecting-sandworm-mode-and-the-emerging-cl/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The title signals research on an emerging attack class targeting AI/ML toolchains — no enrichment signals confirm active exploitation, so no immediate patch or audit action is warranted, but engineers building AI pipelines should read for architectural implications.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> A CrowdStrike post explicitly framed around detection of a named technique (SANDWORM_MODE) likely contains TTPs or behavioral signatures worth converting into detections this quarter; no confirmed IOCs or KEV listing to justify an immediate sweep.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> AI toolchain supply chain attacks as a named, emerging category is useful framing for future policy and budget conversations, but without a confirmed breach or active campaign, no same-week leadership action is required.&lt;/li>
&lt;/ul></description></item><item><title>UAC-0145 (Sandworm) Uses ClickFix CAPTCHAs to Deliver Info-Stealer</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-uac-0145-uses-clickfix-captchas-to-infect-ukrainian-devices/</link><pubDate>Mon, 20 Jul 2026 13:16:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-uac-0145-uses-clickfix-captchas-to-infect-ukrainian-devices/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> ClickFix is a social-engineering technique, not a software vulnerability — no patch or config change applies. Understand the attack pattern (fake CAPTCHA prompts users to paste and run malicious commands) to inform user-awareness training and browser hardening policies.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> ClickFix produces detectable behavioral patterns — browser processes spawning cmd.exe or PowerShell, clipboard-sourced command execution — worth building or tuning detections for this quarter; no specific IOCs were published to support an immediate hunt.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Sandworm/GRU campaign currently focused on Ukrainian targets, making direct exposure unlikely for most US enterprises; useful situational awareness about adversary tradecraft evolution, but no immediate leadership action required.&lt;/li>
&lt;/ul></description></item></channel></rss>