Sandworm Deploys Trojanized WireGuard to Target IT Pros
TL;DR. Russian threat group Sandworm targets IT professionals with a trojanized WireGuard VPN client through fake job offers. - The campaign uses social engineering tactics, moving job offer conversations to Telegram and Zoom for interviews. - Victims receive mock technical assignments requiring connection to a malicious 'corporate' VPN for test tasks. - The customized WireGuard client contains PowerShell code that decrypts and executes additional payloads.
- Sandworm, linked to Russia's APT44, is impersonating IT companies to recruit targets.
- The attack uses fake job offers and social engineering, leading victims to install a malicious VPN client.
- A trojanized WireGuard VPN client, disguised as 'SopraVPN', injects and executes PowerShell code.
- The malicious client uses a custom Base64 alphabet to evade detection and analysis.
Sources
- Sandworm hackers target IT pros with trojanized WireGuard VPN client — bleepingcomputer.com