Sandworm‑Linked UAC‑0145 Uses Fake Job Interviews to Distribute Command‑Capable VPN Malware
What Happened — A Ukrainian CERT report details a new social‑engineering operation by the Sandworm‑linked UAC‑0145 cluster. Actors pose as recruiters, conduct fake job interviews with IT professionals, and persuade victims to install a custom VPN client that grants the attackers remote command execution.
Why It Matters for Compliance & Audit Readiness
- The attack exploits weak access‑control verification and the lack of a documented remote‑access provisioning process—exactly the controls SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations) are designed to protect.
- Continuous evidence of security‑awareness training and VPN usage monitoring provides a defensible audit trail that demonstrates due diligence against social‑engineering threats.
Who Is Affected — IT staff and service providers in the technology sector (including MSPs, MSSPs, and internal IT teams) across Ukraine and potentially other regions targeted by the same campaign.
Recommended Actions
- Map the recruitment‑based phishing scenario to SOC 2 access‑control policies; require documented approval for any remote‑access tool before installation.
- Deploy or refresh security‑awareness training that includes simulated recruiter‑phishing exercises and verification of VPN legitimacy.
- Enable MFA and strict logging on all VPN solutions; integrate logs into a continuous‑monitoring platform for audit evidence.
Technical Notes — The malicious VPN is delivered via a crafted installer linked in the interview follow‑up email. Once installed, it creates a persistent tunnel and accepts arbitrary commands from the threat actor’s C2 server. No public CVE is associated; the vector is purely social engineering.