Sandworm Deploys Trojanized WireGuard to Target IT Pros

TL;DR. Russian threat group Sandworm targets IT professionals with a trojanized WireGuard VPN client through fake job offers. - The campaign uses social engineering tactics, moving job offer conversations to Telegram and Zoom for interviews. - Victims receive mock technical assignments requiring connection to a malicious 'corporate' VPN for test tasks. - The customized WireGuard client contains PowerShell code that decrypts and executes additional payloads.

Sources

Back to QLANKR News