GKRootWire
Security ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm ForecastsSecurity ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm Forecasts
Security

Russian Sandworm Hackers Lure IT Admins With Fake Job Offers, Poisoned VPN Software

The state-linked group is reportedly baiting sysadmins with recruiter messages that deliver a backdoored version of the WireGuard VPN client.

Security researchers say the Sandworm hacking group, widely linked to Russian military intelligence, has spent the past several months running a targeted campaign against system administrators and other IT professionals. The attack starts simply enough: a message posing as a job recruiter, often sent through professional networking channels, that eventually steers the target toward downloading what looks like a legitimate VPN tool.

Instead of the real thing, victims get a modified build of the open-source WireGuard client that has been quietly stitched with malicious code. Because WireGuard is trusted and widely deployed by network administrators, a tampered version can slip past casual scrutiny and hand attackers a foothold on machines that typically have elevated access to internal networks and infrastructure.

The campaign has reportedly been active since at least May, suggesting a sustained effort rather than a one-off phishing blast. Sandworm has a long history of targeting critical infrastructure and enterprise networks, and going after the people who manage VPNs, firewalls, and servers directly is a logical shortcut to broader network compromise.

Why it matters: IT and network admins are high-value targets because compromising their machines often means inheriting the keys to an entire organization's infrastructure. Trojanizing a trusted, open-source tool like WireGuard is a reminder to verify software checksums and download only from official sources, even when a job pitch makes the request feel routine.

Sources: BleepingComputer