Skip to content
supplychainattack.orgSupply chain attack incident catalog
activehigh

Sandworm hackers target IT pros with trojanized WireGuard VPN client

Sandworm threat group has been distributing a trojanized WireGuard VPN client to IT professionals and system administrators since at least May 2026, using fake job offers as a social engineering vector.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
IT professionals and system administrators targeted via trojanized software distribution
Ecosystems
Attack vectors
Threat actor
Affected entities
  • WireGuard VPN clientTrojanized version distributed to targets

The Russian-linked Sandworm threat group has been conducting a targeted campaign against IT professionals and system administrators. The attackers have been using fake job offers as a social engineering mechanism to distribute a trojanized version of the WireGuard VPN client.\n\nThe campaign has been active since at least May 2026, targeting a high-value audience of IT professionals who would have elevated access and credentials within their organizations. By compromising the WireGuard client—a legitimate and widely-trusted VPN application—the attackers could establish persistent access to victim systems and networks.\n\nThis represents a supply chain-adjacent attack where legitimate software distribution channels or user trust in a known application is leveraged to deliver malicious payloads to a targeted professional audience.

Indicators of compromise

Packages
  • WireGuard VPN client (trojanized version)

Remediation

  • Verify the authenticity and source of any WireGuard VPN client downloads; only obtain from official WireGuard repositories
  • Be cautious of unsolicited job offers, especially those requesting software installation or system access
  • Implement application whitelisting and code signing verification for critical software
  • Monitor for suspicious behavior from VPN clients and network tools
  • Review and revoke credentials for any systems that may have executed trojanized WireGuard instances
  • Conduct forensic analysis on systems where the trojanized client may have been installed

Sources

  1. Sandworm hackers target IT pros with trojanized WireGuard VPN client · BleepingComputer

Cite this entry

"Sandworm hackers target IT pros with trojanized WireGuard VPN client." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed May 1, 2026; last updated August 11, 2026. https://supplychainattack.org/incident/sandworm-hackers-target-it-pros-with-trojanized-wireguard-vpn-client-39oqkh

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. activecritical

    ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2

    ChainDrop is a self-propagating npm worm that publishes malicious versions of dozens of npm packages using stolen maintainer credentials. The worm harvests CI/CD credentials and uses an Ethereum-based dead-drop command-and-control mechanism.

    ChaindropnpmOtherCompromised packageMalicious maintainerAccount takeover
  2. containedhigh

    Online ad firm Adform’s script compromised to steal cryptocurrency

    Adform's advertising script was compromised in a supply-chain attack that injected cryptocurrency-stealing code. The malicious script intercepted wallet addresses copied to visitors' clipboards and replaced them with attacker-controlled addresses, affecting all websites using Adform's ad platform.

    OtherCompromised package
  3. containedcritical

    Malicious code in @antv/gatsby-theme (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gatsby-theme. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  4. activecritical

    Malicious code in @antv/gi-assets-hugegraph (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-hugegraph. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit