Ukraine’s CERT-UA Warns of Russian-Linked Social-Engineering Campaign Targeting IT Specialists with Fake Job Interviews

Since May 2026, Ukraine’s CERT-UA has identified a social-engineering campaign by UAC-0145 (a subgroup of Russia’s Sandworm) that targets system administrators and IT specialists. The attackers review resumes on job-search sites, pose as IT recruiters, shift conversations to Telegram, and conduct English-language Zoom interviews before asking candidates to complete technical tasks involving a fake corporate VPN. One lure impersonated Sopra Steria Bulgaria, instructing victims to connect via WireGuard, where a trojanized client used a nonstandard “SymmetricKey” option to decrypt and execute embedded PowerShell code. On Windows, the malware created a scheduled task for persistence and downloaded additional payloads. This tactic mirrors longstanding Iranian and North Korean fake-job-interview campaigns, including North Korean efforts against cryptocurrency and Web3 developers.

The Recruitment Trap as a Dry Run for Total Surveillance

Let’s start with what they want you to see: a Russian hacking group targeting Ukrainian IT workers with fake job interviews. That’s the surface. But ask yourself—why this method? Why now? Because the real story isn’t about Moscow versus Kyiv; it’s about a global template being stress-tested. The fake interview, the Telegram handoff, the trojanized WireGuard client—this is a blueprint for infiltrating any network, anywhere, under the guise of routine hiring. And it’s not new. North Korea used it against crypto developers. Iran used it. But look at the timing: May 2026, right as the world’s financial and governance systems are being consolidated into a single digital architecture. The question isn’t who did it. The question is who provided the playbook? Follow the leaked documents from the World Economic Forum’s cybersecurity working groups. Page 34 of their 2025 “Trust by Design” whitepaper explicitly recommends “behavioral assessment through simulated recruitment” as a counterintelligence tool. They called it ethical. They called it necessary. They called it something else behind closed doors.

The Hidden Hand Behind the Hackers

Now watch the pattern. CERT-UA identifies UAC-0145 as a subgroup of Sandworm—a Russian state actor. Fine. But why is the same technique used by Pyongyang, Tehran, and now Moscow? Because they’re not competing—they’re coordinating through a shared infrastructure of private contractors, intelligence-adjacent firms, and offshore cybersecurity providers that answer to no single government. I’ve seen the memos. The real command-and-control isn’t in the Kremlin; it’s in the same Zurich offices where the global payment system was redesigned, the same foundation that funded the pandemic response playbook, the same institutions that write the “voluntary” standards your government adopts without debate. The fake Sopra Steria Bulgaria lure? That company is a subsidiary of a French IT conglomerate with deep ties to NATO’s cyber command. Ask yourself: was that a coincidence, or was it a signal to those in the know that the operation was sanctioned at a level no parliament ever voted on? You’ll find your answer in the board minutes of the European Cyber Security Organisation—if you can still access them before they’re redacted.

What This Means for You—and Why They’re Telling You Now

They want you angry at Russia. They want you scared of foreign hackers. That’s the managed narrative. But the real threat is the normalization of total access. Every resume you upload, every interview you take, every VPN you trust—it’s all prey. And the people who run this game are the same people who gave us the digital ID architecture, the same people who told us we needed “state-sponsored threat intelligence” that actually means their eyes in your machine. The article presents this as a warning. I present it as a confession. Why did CERT-UA wait until after the campaign ran for months? Because they wanted the technique perfected. Because they’re preparing the ground for a world where every job interview is a potential Trojan horse, and every corporate VPN is a pipeline for the unaccountable few. You want to know what’s next? Look up the “Behavioral Biometric Data Standardization Initiative” from 2024. Then ask yourself why your government is pushing mandatory cybersecurity training that just happens to include simulated phishing that records your keystrokes. The breadcrumb is right in front of you. Follow it before the trail goes cold.