threat-intel
Russian military hackers pose as recruiters to target Ukrainian IT workers
High
Summary
Russian military hackers, linked to the Sandworm group (APT44/Seashell Blizzard), are impersonating IT recruiters to target Ukrainian IT workers and install malicious software. The operation involves using legitimate job sites, Telegram, and a custom VPN application (SopraVPN) to gain access to victims' systems. CERT-UA is investigating the campaign, which has been ongoing since May, and the hackers are attempting to compromise corporate networks.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
