Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Sandworm Threat Group Deploys Trojanized WireGuard VPN Client via Fake Job Offers to Compromise IT Professionals

Sandworm’s UAC‑0145 sub‑cluster is using bogus recruitment offers to deliver a malicious WireGuard client (“SopraVPN”) that installs hidden PowerShell or cURL payloads. The tactic targets IT staff with VPN access, highlighting the need for strict SOC 2 access‑control enforcement and continuous device monitoring.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

Sandworm Threat Group Deploys Trojanized WireGuard VPN Client via Fake Job Offers to Compromise IT Professionals

What Happened — Sandworm’s UAC‑0145 sub‑cluster has been luring system administrators and IT staff with bogus job postings. Victims are moved to Telegram and Zoom, given a mock technical assignment, and asked to download a “SopraVPN” client from SourceForge. The client is a modified WireGuard binary that executes hidden PowerShell (Windows) or cURL (Linux) payloads once installed.

Why It Matters for Compliance & Audit Readiness

  • The campaign exploits weak access‑control policies and the lack of verified device posture before allowing VPN connections – a classic SOC 2 CC6.1 (Logical Access) failure.
  • Continuous monitoring of endpoint security (EDR) and strict “managed‑device only” VPN rules provide the audit evidence needed to demonstrate effective access‑control enforcement.

Who Is Affected – IT service providers, telecom operators, managed‑service firms, and any organization that grants VPN access to contractors or remote staff.

Recommended Actions –

  • Enforce a policy that only devices enrolled in your EDR solution may establish VPN tunnels.
  • Implement MFA and Just‑In‑Time (JIT) provisioning for VPN credentials, and log all connection attempts for SOC 2 audit trails.
  • Conduct security‑awareness training focused on recruitment‑based social engineering.

Source: BleepingComputer

Technical Notes – The trojan replaces WireGuard’s Base64 decoder with a custom alphabet, hides a “SymmetricKey” option that decrypts PowerShell, creates a scheduled task on Windows, and uses cURL on Linux to fetch additional payloads via the VPN tunnel. Source: same as above

📰 Original Source
https://www.bleepingcomputer.com/news/security/sandworm-hackers-target-it-pros-with-trojanized-wireguard-vpn-client/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →