Fake Recruiters Push ‘SopraVPN’ Malware in Interviews

The Hacker News · High sophistication
Last updated August 11, 2026

Ukrainian CERT says Sandworm-linked actors (UAC-0145) posed as recruiters to lure IT workers into a fake hiring process. Victims were guided from job-site chats to Telegram and Zoom, then emailed “VPN assessment” files that pushed a trojanized WireGuard-based VPN client capable of silently running commands on the victim’s computer.

Key findings

  • Attackers posed as recruiters on job sites, targeting Ukrainian system administrators and IT specialists.
  • Conversation moved from job-site chat to Telegram with a supposed HR manager, then to Zoom interviews.
  • Victims received an email with VPN configuration files (WireGuard) as part of a ‘technical assessment.’
  • When configs ‘failed,’ attackers directed victims to download a custom VPN client (‘SopraVPN’) via a fake lookalike domain and SourceForge projects.
  • The modified WireGuard client could decrypt and execute PowerShell commands on the victim host without their knowledge.
  • Windows variant created a scheduled task to download a secondary payload; Linux variant used cURL to download an executable over the VPN.

Who’s being targeted

  • Commonly targeted roles: IT, System Administrators, Security/IT Operations, Helpdesk, Engineering, HR/Recruiting teams (for awareness of recruiter impersonation).
  • Affected industries: IT services, Technology, Government (Ukraine-focused targeting).
  • Attack channels: website, telegram, email, zoom.
  • Impersonated: Recruiter / HR manager for Sopra Steria Bulgaria (and an IT company such as ATLAS Business Group), Sopra Steria Bulgaria / Sopra Steria corporate IT.

Awareness takeaways

  • Treat recruiter-driven requests to install software (VPNs, “assessment tools”) as high risk and verify through official company channels.
  • Watch for lookalike domains and third-party download hosting when asked to install “corporate” tools.
  • Limit access to company resources to managed, monitored devices, especially for IT staff with elevated privileges.

Red flags to watch for

  • Hiring process quickly moves to Telegram and relies on off-platform coordination
  • Unusual requirement to install/use provided VPN configs as part of an interview
  • Unclear identity of interviewer (possible synthetic persona)
  • Lookalike domain (soprasteria-bg[.]com) used instead of an official corporate domain
  • Software download hosted via third-party project pages (SourceForge) for a ‘corporate VPN’
  • Pressure to install an unfamiliar VPN client to proceed with the interview
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re in a Zoom interview, recruiter says, “To start the technical test, connect to our corporate VPN.” Sounds legit, right? CERT Ukraine saw fake recruiters for Sopra Steria Bulgaria push IT admins from job sites to Telegram, then Zoom, then email you WireGuard VPN configs as a ‘technical assessment.’ When they ‘fail,’ you’re told to install a special client called SopraVPN. Here’s the catch: SopraVPN comes from a fake domain, soprasteria-bg[.]com, and a SourceForge project. It’s a trojanized WireGuard client that can silently run PowerShell commands and scheduled tasks on your machine while you think you’re just doing an interview. If any recruiter asks you to install a VPN or ‘assessment tool’ like SopraVPN, stop and verify through the company’s official website or HR contacts, before you install anything.

Similar attacks

Fake GitHub Repos and Trojan Apps Steal Data

Fake GitHub Repos and Trojan Apps Steal Data

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to trick people into installing credential and crypto-stealing malware, and another uses hundreds of imposter GitHub repositories to lure…

July 17, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake CAPTCHA Tricks Ukrainians Into Running Malware

Fake CAPTCHA Tricks Ukrainians Into Running Malware

CERT-UA reports a Sandworm-linked group (UAC-0145) is using fake CAPTCHA checks on compromised websites to persuade Ukrainian visitors to run PowerShell commands that infect their own computers. The campaign also includes Android attacks where victims are sent trojan APK “security tools” via…

July 19, 2026
Fake Zoom/Webex Installers Drop Starland RAT

Fake Zoom/Webex Installers Drop Starland RAT

Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools like Zoom, Webex, and MobaXterm. Victims are socially engineered via a “ClickFix” style trick into running a command that silently…

July 17, 2026
Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026
Larva-24009 Lures Firms With Fake Doc Attachments

Larva-24009 Lures Firms With Fake Doc Attachments

AhnLab reports Larva-24009 has continued phishing campaigns through 2026, sending emails that trick employees into opening fake “document” attachments that are actually shortcut (LNK) files. When opened, the attachment runs hidden PowerShell commands, shows a decoy document, and silently downloads…

August 3, 2026