cyber securityCyber Security NewsMalware 2 min.Read Fake Corporate VPN Test Creates Scheduled Task and Downloads Malware on Windows By Mayura Kathir August 12, 2026 An advanced recruitment-themed intrusion campaign attributed to UAC-0145, a cluster that includes subcluster UAC-0002, also tracked as Sandworm, APT44 and Seashell Blizzard. The activity, observed since at least May 2026, begins on job-search platforms. Operators review a candidate’s résumé, contact the individual while impersonating an IT company such as ATLAS Business Group, and move the conversation from the platform’s chat feature to Telegram.

A purported HR representative conducts an initial screening, asking routine questions about work arrangements and English-language proficiency. Victims are then invited to a Zoom meeting. The call is not merely a lure.

CERT-UA said the meeting is held with a real English-speaking participant, reportedly a man aged about 30 to 35. That human interaction adds legitimacy and makes the subsequent technical-interview instructions harder to dismiss as a conventional phishing attempt. Victims next receive an email containing WireGuard configurations for a supposed corporate VPN, ostensibly required to complete test tasks.

The message also includes a support Zoom link. In the documented case, the sender used mike.weitzman@soprasteria-bg[.]com, a domain crafted to resemble regional branding for Sopra Steria, whose legitimate domains include soprasteria[.]com and soprasteria[.]bg. The trojanized application is built from WireGuard source code but contains changes that transform configuration parsing into a covert code-execution path.

Example of primary interaction (Source : CERT-UA). CERT-UA Researchers said that, the operation targets system administrators and IT specialists through a highly credible, multi-stage hiring process designed to turn a technical interview into a malware delivery mechanism. Most notably, the modified client accepts a non-standard SymmetricKey configuration option.

Its Base64-encoded value carries an AES-256-GCM nonce, ciphertext and authentication tag. Fake Corporate VPN Test The client decodes the PrivateKey value into a 32-byte AES key, decrypts embedded PowerShell, and passes that script to WireGuard’s runScriptCommand mechanism, normally used for directives such as PostUp. Example of email correspondence (Source : CERT-UA).

The operators also altered Base64 handling to impede inspection. PrivateKey and PublicKey fields use a custom 64-character alphabet generated through Fisher-Yates shuffling. The shuffle is seeded with the CRC32 value of “SymmetricKey,” enabling the malware to permute the standard alphabet before parsing key material.

This layered design conceals the payload within what appears to be a valid VPN profile. On Windows, the decrypted PowerShell creates a scheduled task and retrieves a second-stage payload from an internet-hosted URL. On Linux, the counterpart uses cURL to download an executable from attacker-controlled infrastructure over the VPN; the configuration supplies the DNS server address required to reach it.

The campaign demonstrates why recruitment workflows are now a high-value attack surface, especially for privileged technical staff. Organizations should permit corporate-resource access only from managed endpoints with EDR coverage, enforced security policies and continuous monitoring. Hiring teams and IT professionals should independently verify domains, software provenance and interview-task requirements before executing software or importing network configurations.

CERT-UA’s official advisory also underscores that a video call, a polished website and a public hosting service do not validate a recruiter or a VPN client. Security teams should hunt for unexpected scheduled-task creation, unsigned WireGuard-derived binaries, anomalous PowerShell spawned by VPN software, and created profiles across endpoints. Security teams must treat configuration files as executable content, not benign artifacts. [Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model. -> Register Now Tagscyber securityCyber Security NewsMalware Mayura Kathirhttps://gbhackers.com/Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week Infosec- Resources How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities June 4, 2023 1 What is Deep Web The deep web, invisible web, or... SOC Architecture How to Build and Run a Security Operations Center (SOC Guide) – 2023 June 3, 2023 12 Today’s Cyber security operations center (CSOC) should have everything... Cyber Security News Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component October 18, 2023 0 TeamViewer's popularity and remote access capabilities make it an...

Checklist Web Server Penetration Testing Checklist – 2026 January 6, 2026 0 Web server pentesting is performed under three significant categories: identity,... Infosec- Resources ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities June 4, 2023 4 ATM Penetration testing, Hackers have found different approaches to... TopicsAcquisitionAdobeAdwareAIAmazonAmazon AWSAMDAndroidAnti VirusAntimalwareANY RUNApacheAPIAppleAPTArtificial IntelligenceAvastAWSAzureBackdoorBitcoinBluetoothBotnetBrowserBuffer over flowBug BountyBusinessChatbotsChatGPTChecklistChromeCiscoCISOCISO AdvisoryCloudCloud SecurityCloudflareComputer SecurityCourseCPUCross site ScriptingcryptocurrencyCryptocurrency hackCVE/vulnerabilityCyber AdvisoryCyber AICyber AttackCyber Crimecyber securityCyber security CourseCyber Security NewsCyber Security ResourcesCybersecurity NewsletterDark WebData BreachData GovernanceDDOSDealsDeepSeekDiscordDNSDos AttackDriveDropboxEducationEmailEmail SecurityEthical HackingExploitExploitation ToolsExtratorrentsFACEBOOKFeaturedFirefoxFirefox NewsFirewallForensics ToolsgameGenAIGitHubGitLabGmailGoogleGoogle dorksGovernanceGRCHacking BooksHacksHardware HackingHBOHTMLHTTPIBMIISIncident ResponseInformation GatheringInformation Security RisksInfosec- ResourcesInsider ThreatsInstagramMore Cyber Security News Microsoft Patch Tuesday Update August 2026 Fixes Actively Exploited Windows Zero-Day 0 Microsoft’s August 2026 Patch Tuesday released fixes for hundreds...

Cyber Security News DEF CON Attendees Allegedly Jam Plane Wi‑Fi, Launch ‘Evil Twin’ Phishing Attack 0 A Delta Air Lines flight returning travelers from Las... CVE/vulnerability Zoom Zero-Click ‘Zoomsday’ Flaw Lets Meeting Participants Execute Code on Other Users’ Devices 0 Zoom has released security updates to address four vulnerabilities... cyber security One ClickFix Lure Can Give Hackers a Persistent Remote Shell Through New CNCMachineRMS RAT 0 A ClickFix prompt can end in a remote-access foothold.... CVE/vulnerability Docker CopyEscape Vulnerability Enables Host File Overwrite and Root Code Execution 0 A critical vulnerability in Docker, tracked as CVE-2026-17106 and...

AI LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Target 0 The March 2026 compromise of LiteLLM was more than... Cyber Security News Plug & Pwn Attack Exploits Windows PnP to Gain SYSTEM Access With Zero Clicks 0 Security researchers Alejandro Hernando, also known as 0xedh, and... CVE/vulnerability Copeland XWEB Pro Vulnerabilities Let Attackers Gain Root Access and Manipulate Refrigeration Systems 0 Security researchers have discovered 23 vulnerabilities in Copeland’s XWEB...

Related Articles Microsoft Patch Tuesday Update August 2026 Fixes Actively Exploited Windows Zero-Day Cyber Security News August 12, 2026 DEF CON Attendees Allegedly Jam Plane Wi‑Fi, Launch ‘Evil Twin’ Phishing Attack Cyber Security News August 12, 2026 Zoom Zero-Click ‘Zoomsday’ Flaw Lets Meeting Participants Execute Code on Other Users’ Devices CVE/vulnerability August 12, 2026 One ClickFix Lure Can Give Hackers a Persistent Remote Shell Through New CNCMachineRMS RAT cyber security August 12, 2026 Docker CopyEscape Vulnerability Enables Host File Overwrite and Root Code Execution CVE/vulnerability August 12, 2026 Recent News Microsoft Patch Tuesday Update August 2026 Fixes Actively Exploited Windows Zero-Day Divya - August 12, 2026 DEF CON Attendees Allegedly Jam Plane Wi‑Fi, Launch ‘Evil Twin’ Phishing Attack Divya - August 12, 2026 Zoom Zero-Click ‘Zoomsday’ Flaw Lets Meeting Participants Execute Code on Other Users’ Devices Divya - August 12, 2026 One ClickFix Lure Can Give Hackers a Persistent Remote Shell Through New CNCMachineRMS RAT Mayura Kathir - August 12, 2026 Docker CopyEscape Vulnerability Enables Host File Overwrite and Root Code Execution Divya - August 12, 2026 LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Target Mayura Kathir - August 11, 2026