Russian military hackers pose as recruiters to target Ukrainian IT workers
Hackers linked to Russia’s military intelligence unit are posing as recruiters to trick Ukrainian IT workers into installing malicious software, researchers have found.
Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency.
The operation mostly targets system administrators and other IT professionals. According to CERT-UA, the hackers search legitimate Ukrainian job sites for potential victims, review their resumes and then contact them while posing as recruiters for an IT company.
In one case investigated by the agency, the attackers claimed to represent a recruitment company called Atlas Business Group and told a potential victim they were hiring for a project involving Sopra Steria Bulgaria, part of a legitimate international IT services company.
After making initial contact through a job website’s built-in chat, the purported recruiters moved the conversation to Telegram. There, a fake HR manager conducted an initial screening, asking ordinary questions about the candidate’s preferred work arrangements and English-language skills.
The candidate was then invited to a Zoom interview, which involved an English-speaking man who appeared to be between 30 and 35 years old. The agency did not say whether the person appearing in the interview was a genuine participant in the operation or an AI-generated persona.
As the recruitment process continued, the hackers emailed the candidate instructions for what they claimed was a technical interview. According to the research, the victim was told to connect to a corporate network using WireGuard, a legitimate open-source VPN protocol and software, in order to complete test assignments.
The sender’s email address was crafted to resemble one belonging to a regional Sopra Steria office.
When candidates tried to connect using the provided files, they encountered errors. The supposed recruiter then told them to download a custom VPN app called SopraVPN, hosted on the software distribution platform SourceForge and linked from a website designed to look like the company’s official site.
Installing SopraVPN was the critical step in compromising the victim’s computer, CERT-UA said.
The hackers created the application using legitimate WireGuard open-source code but modified it so that malicious commands could be covertly executed on a victim’s device. Some commands were encrypted and embedded in the VPN configuration files, making them harder to identify during a basic inspection.
CERT-UA did not disclose how many people had been targeted or identify the hackers’ ultimate objective. The Telegram account used by the purported Atlas Business Group recruiter was accessible at the time of writing, but the associated job advertisement had been removed.
Sandworm, also tracked by researchers as APT44 and Seashell Blizzard, has been active for more than a decade and has been blamed for some of Russia’s most disruptive cyber operations, including attacks on Ukraine’s electricity grid.
The group is not alone in using fake recruitment campaigns as a way to gain access to targeted systems.
Western intelligence agencies have previously warned that Chinese intelligence officers have posed as recruiters and consultants on professional networking and job platforms to approach government, military and other personnel with access to sensitive information.
North Korean hackers have also repeatedly impersonated recruiters in campaigns designed to steal credentials and cryptocurrency or compromise employees at technology companies. In other operations, North Korean IT workers have sought employment at foreign companies under false identities to generate revenue for Pyongyang.
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.



