On August 8, 2026, CERT-UA published an analysis of UAC-0145, a Sandworm-linked cluster active since at least May 2026. According to The Record, the operators posed as recruiters from "Atlas Business Group" and a fake Bulgarian office of Sopra Steria. They made first contact on job sites, moved candidates to Telegram for a fake HR screening, and then invited them to Zoom interviews. Candidates were told to install a VPN client called "SopraVPN" for a technical assessment.
The campaign is interesting less for its malware than for its target. The attackers went after system administrators and other IT specialists, the people who hold privileged access to Ukrainian networks. It also shows how far Ukraine's public cyber-defence posture has developed since the invasion.
What CERT-UA found
Per The Hacker News, SopraVPN is a modified WireGuard client hosted on SourceForge under three project names, supported by a lookalike domain, soprasteria-bg[.]com. The altered build accepts a non-standard "SymmetricKey" option carrying BASE64-encoded AES-256-GCM data. That lets it run commands hidden in the configuration's PostUp field. On Windows it creates scheduled tasks that fetch further payloads, and on Linux it uses cURL. CERT-UA's advisory recommends that organisations restrict corporate access to managed devices with security software and keep monitoring continuous.
The Record notes that CERT-UA did not disclose how many people were targeted or the attackers' ultimate objective. That candour is worth noting. The agency published what it could verify and did not pad the report with speculation.
The case for heavier state control
The strongest argument for a more interventionist approach runs as follows. If a state-backed adversary can reach a sysadmin through an ordinary job-site chat, voluntary hygiene is not enough. Governments should mandate device controls, restrict what software engineers may install, and give security services broad authority over the private sector. Ukraine has moved some way in this direction. Law #11290, passed on March 27, 2025 with 240 votes according to the Kyiv Independent, creates a national incident-response system. It establishes cyber-defence units within state bodies and critical infrastructure, and it sets up national, sectoral and regional response teams aligned with the EU's NIS2 directive.
That structure is sensible. Clear roles during a crisis are what separate a coordinated response from a scramble.
Why publication beats mandate
The hook shows the limits of the mandate-first approach, though. This lure works through a personal career decision on a personal device, in a Telegram chat or a Zoom call. No statute can inspect that moment. A compliance checklist for critical-infrastructure operators does not reach a freelance administrator weighing a job offer at midnight.
What does reach that person is fast, specific, public information. CERT-UA named the cluster, described the tradecraft, listed the fake brands and the infrastructure, and explained the mechanism. Other defenders can turn that into detections and training. Prospective victims can check a recruiter's story against a known pattern. Trust is built this way, and it costs the private sector nothing in speech or innovation. It is also the model Ukraine's 2021 Cybersecurity Strategy set out: it rests on deterrence, cyber resilience and interaction, and it explicitly extends the defensive effort to "business entities, public associations, and individual citizens."
The volume of activity explains why that breadth matters. CSIS reports that attacks on Ukrainian infrastructure surged by nearly 70% in 2024, with over 1,000 attacks tracked against government, military and civilian targets. A state security service cannot personally shield every engineer against that flow. It can, however, keep the whole community informed.
Where regulation should and should not go
Three implications follow for policy.
- Keep attribution and technical disclosure as the default. Naming a Sandworm sub-cluster and publishing its infrastructure carries little cost and builds a shared defensive picture. It should be protected from being crowded out by classification instincts, except where an active operation truly requires secrecy.
- Aim mandates at organisations, not individuals. Managed-device requirements for privileged access, which CERT-UA itself recommends, are proportionate because they bind the employer that controls the endpoint. Rules that tried to police what individual engineers do in their private job searches would be unenforceable and would push talent abroad.
- Treat the civilian tech workforce as a partner. CSIS notes that the proposed Cyber Force would include a reserve of civilian technology security experts. That is the right instinct. The same people being targeted are also Ukraine's deepest source of defensive capacity, and legislation should draw them in with clear legal footing and not with blanket obligations.
The cyber-force bill, submitted in December 2024 and passed at first reading on October 9, 2025 according to CSIS, still needs a second vote. Its drafters should preserve the openness that the CERT-UA report demonstrates. A military structure is valuable for coordination, but the public-facing analysis is what reaches a sysadmin before the fake recruiter does.
What to watch
CERT-UA has not said what the attackers wanted from these administrators, and that gap matters. Compromised sysadmins are stepping stones into networks, and the eventual objective could be espionage or disruption. The next disclosure should show whether the agency can tie this cluster to specific intrusions and whether the guidance about managed devices is being adopted by employers.
The lasting lesson is that wartime resilience is a property of people and process as much as of hardened systems. Ukraine's best defence against fake recruiters is a security agency that publishes what it learns, and a policy framework that keeps it doing so.