Ukraine Ukraine wartime cyber resilience

Ukraine's Public Attribution of Sandworm's Fake-Recruiter Campaign Shows Cyber Resilience Now Depends on Individual Engineers

CERT-UA's dissection of UAC-0145's SopraVPN lure shows wartime defence must extend to the people running networks, not just the networks themselves.

Ukraine's Cyber Defence in Numbers People of Internet Research · Ukraine ~70% Rise in attacks, 2024 Attacks on Ukrainian infrastructur… 240 Votes for cyber law Law #11290 passed on March 27, 202… 3 Fake SopraVPN projects Trojanised clients were hosted und… peopleofinternet.com
Ukraine's Cyber Defence in Numbers People of Internet Research · Ukraine ~70% Rise in attacks, 2024 240 Votes for cyber law 3 Fake SopraVPN projects peopleofinternet.com

Key Takeaways

On August 8, 2026, CERT-UA published an analysis of UAC-0145, a Sandworm-linked cluster active since at least May 2026. According to The Record, the operators posed as recruiters from "Atlas Business Group" and a fake Bulgarian office of Sopra Steria. They made first contact on job sites, moved candidates to Telegram for a fake HR screening, and then invited them to Zoom interviews. Candidates were told to install a VPN client called "SopraVPN" for a technical assessment.

The campaign is interesting less for its malware than for its target. The attackers went after system administrators and other IT specialists, the people who hold privileged access to Ukrainian networks. It also shows how far Ukraine's public cyber-defence posture has developed since the invasion.

What CERT-UA found

Per The Hacker News, SopraVPN is a modified WireGuard client hosted on SourceForge under three project names, supported by a lookalike domain, soprasteria-bg[.]com. The altered build accepts a non-standard "SymmetricKey" option carrying BASE64-encoded AES-256-GCM data. That lets it run commands hidden in the configuration's PostUp field. On Windows it creates scheduled tasks that fetch further payloads, and on Linux it uses cURL. CERT-UA's advisory recommends that organisations restrict corporate access to managed devices with security software and keep monitoring continuous.

The Record notes that CERT-UA did not disclose how many people were targeted or the attackers' ultimate objective. That candour is worth noting. The agency published what it could verify and did not pad the report with speculation.

The case for heavier state control

The strongest argument for a more interventionist approach runs as follows. If a state-backed adversary can reach a sysadmin through an ordinary job-site chat, voluntary hygiene is not enough. Governments should mandate device controls, restrict what software engineers may install, and give security services broad authority over the private sector. Ukraine has moved some way in this direction. Law #11290, passed on March 27, 2025 with 240 votes according to the Kyiv Independent, creates a national incident-response system. It establishes cyber-defence units within state bodies and critical infrastructure, and it sets up national, sectoral and regional response teams aligned with the EU's NIS2 directive.

That structure is sensible. Clear roles during a crisis are what separate a coordinated response from a scramble.

Why publication beats mandate

The hook shows the limits of the mandate-first approach, though. This lure works through a personal career decision on a personal device, in a Telegram chat or a Zoom call. No statute can inspect that moment. A compliance checklist for critical-infrastructure operators does not reach a freelance administrator weighing a job offer at midnight.

What does reach that person is fast, specific, public information. CERT-UA named the cluster, described the tradecraft, listed the fake brands and the infrastructure, and explained the mechanism. Other defenders can turn that into detections and training. Prospective victims can check a recruiter's story against a known pattern. Trust is built this way, and it costs the private sector nothing in speech or innovation. It is also the model Ukraine's 2021 Cybersecurity Strategy set out: it rests on deterrence, cyber resilience and interaction, and it explicitly extends the defensive effort to "business entities, public associations, and individual citizens."

The volume of activity explains why that breadth matters. CSIS reports that attacks on Ukrainian infrastructure surged by nearly 70% in 2024, with over 1,000 attacks tracked against government, military and civilian targets. A state security service cannot personally shield every engineer against that flow. It can, however, keep the whole community informed.

Where regulation should and should not go

Three implications follow for policy.

The cyber-force bill, submitted in December 2024 and passed at first reading on October 9, 2025 according to CSIS, still needs a second vote. Its drafters should preserve the openness that the CERT-UA report demonstrates. A military structure is valuable for coordination, but the public-facing analysis is what reaches a sysadmin before the fake recruiter does.

What to watch

CERT-UA has not said what the attackers wanted from these administrators, and that gap matters. Compromised sysadmins are stepping stones into networks, and the eventual objective could be espionage or disruption. The next disclosure should show whether the agency can tie this cluster to specific intrusions and whether the guidance about managed devices is being adopted by employers.

The lasting lesson is that wartime resilience is a property of people and process as much as of hardened systems. Ukraine's best defence against fake recruiters is a security agency that publishes what it learns, and a policy framework that keeps it doing so.

Sources & Citations

  1. CERT-UA advisory on UAC-0145 (Aug 10, 2026)
  2. NSDC of Ukraine: Cybersecurity Strategy (2021)
  3. The Record: Russian military hackers pose as recruiters
  4. The Hacker News: UAC-0145 fake job interviews
  5. Kyiv Independent: Parliament passes cybersecurity bill
  6. CSIS: Ukraine's future cyber and space forces