HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Sandworm‑Linked UAC‑0145 Uses Fake Job Interviews to Distribute Command‑Capable VPN Malware

UAC‑0145, a Sandworm subgroup, masquerades as recruiters to trick IT workers into installing a malicious VPN that grants remote command execution. The campaign highlights gaps in access‑control verification and security‑awareness—key SOC 2 controls.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Sandworm‑Linked UAC‑0145 Uses Fake Job Interviews to Distribute Command‑Capable VPN Malware

What Happened — A Ukrainian CERT report details a new social‑engineering operation by the Sandworm‑linked UAC‑0145 cluster. Actors pose as recruiters, conduct fake job interviews with IT professionals, and persuade victims to install a custom VPN client that grants the attackers remote command execution.

Why It Matters for Compliance & Audit Readiness

  • The attack exploits weak access‑control verification and the lack of a documented remote‑access provisioning process—exactly the controls SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations) are designed to protect.
  • Continuous evidence of security‑awareness training and VPN usage monitoring provides a defensible audit trail that demonstrates due diligence against social‑engineering threats.

Who Is Affected — IT staff and service providers in the technology sector (including MSPs, MSSPs, and internal IT teams) across Ukraine and potentially other regions targeted by the same campaign.

Recommended Actions

  • Map the recruitment‑based phishing scenario to SOC 2 access‑control policies; require documented approval for any remote‑access tool before installation.
  • Deploy or refresh security‑awareness training that includes simulated recruiter‑phishing exercises and verification of VPN legitimacy.
  • Enable MFA and strict logging on all VPN solutions; integrate logs into a continuous‑monitoring platform for audit evidence.

Source: The Hacker News – Sandworm‑Linked UAC‑0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

Technical Notes — The malicious VPN is delivered via a crafted installer linked in the interview follow‑up email. Once installed, it creates a persistent tunnel and accepts arbitrary commands from the threat actor’s C2 server. No public CVE is associated; the vector is purely social engineering.

📰 Original Source
https://thehackernews.com/2026/08/sandworm-linked-uac-0145-uses-fake-job.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →