Summary
- CERT-UA attributes the activity to UAC-0145, which it associates with the wider UAC-0002/Sandworm activity set.
- System administrators and other IT workers are approached through credible recruitment before being directed towards attacker-controlled technical exercises.
- The campaign targets technical privilege through professional trust, often outside the systems and channels monitored by an employer.
Russian military-linked hackers are posing as recruiters and running credible hiring processes to target Ukrainian IT professionals, according to CERT-UA, using the routines of technical recruitment as an initial-access mechanism.
CERT-UA attributes the campaign to the UAC-0145 threat cluster, which it associates with the wider UAC-0002 activity set tracked elsewhere as Sandworm, APT44, or Seashell Blizzard. The Ukrainian authority says the recruitment activity has been operating since at least May.
The campaign primarily targets system administrators and other technical specialists whose roles can provide access to infrastructure, credentials, administrative tools, or sensitive organisational information.
Rather than beginning with a conventional unsolicited attachment, the attackers search legitimate employment platforms for suitable candidates and make contact using realistic vacancies. In an example investigated by CERT-UA, the conversation moved from a job site’s messaging system to Telegram and included an ordinary-looking discussion with a purported human-resources representative.
The attackers then moved the candidate towards a supposed technical assessment. Reporting based on CERT-UA’s investigation describes instructions to connect to what was presented as corporate infrastructure using WireGuard configuration files, with spoofed infrastructure used to reinforce the recruitment pretext.
The approach exploits a difficult security boundary. Recruitment often takes place through personal email, messaging applications, professional-network accounts, and privately owned devices before an employer has any visibility into the interaction.
Technical applicants also have legitimate reasons to execute code, review repositories, install tools, connect to test systems, or alter local configuration during an interview process. Requests that would look immediately suspicious in another business function can therefore appear plausible when directed at a system administrator or developer.
The objective is not simply to obtain personal data from the candidate. Technical workers can themselves become a route towards organisational access because their accounts, devices, and professional knowledge may connect directly to infrastructure the attacker ultimately wants to reach.
That places identity and privilege outside the conventional enterprise perimeter. An employee can be targeted because of their corporate role while the social engineering unfolds through services the employer does not own or monitor. By the time activity reaches organisational systems, much of the trust-building stage may already have succeeded.
The campaign also fits a wider pattern in which state-linked operators tailor approaches to the professional context of high-value targets. Recruitment offers, conference invitations, project discussions, and other credible work interactions provide a more durable pretext than generic phishing because they create an explanation for continued contact and technically unusual requests.
Attribution remains an assessment by CERT-UA. The agency links UAC-0145 with the UAC-0002/Sandworm activity set associated by governments and security researchers with Russian military intelligence, but the disclosure does not establish how many targets were successfully compromised through this specific recruitment operation.
The campaign’s significance lies in the access route it exploits: administrators and other technically privileged staff may be exposed not only through corporate email and managed endpoints, but through their professional identity and the ordinary hiring activity that surrounds it.



