Sandworm hackers target IT pros with trojanized WireGuard VPN client
Sandworm threat group has been distributing a trojanized WireGuard VPN client to IT professionals and system administrators since at least May 2026, using fake job offers as a social engineering vector.
- Disclosed
- Last updated
- Blast radius
- IT professionals and system administrators targeted via trojanized software distribution
- Ecosystems
- Attack vectors
- Threat actor
- Affected entities
- WireGuard VPN clientTrojanized version distributed to targets
The Russian-linked Sandworm threat group has been conducting a targeted campaign against IT professionals and system administrators. The attackers have been using fake job offers as a social engineering mechanism to distribute a trojanized version of the WireGuard VPN client.\n\nThe campaign has been active since at least May 2026, targeting a high-value audience of IT professionals who would have elevated access and credentials within their organizations. By compromising the WireGuard client—a legitimate and widely-trusted VPN application—the attackers could establish persistent access to victim systems and networks.\n\nThis represents a supply chain-adjacent attack where legitimate software distribution channels or user trust in a known application is leveraged to deliver malicious payloads to a targeted professional audience.
Indicators of compromise
- Packages
- WireGuard VPN client (trojanized version)
Remediation
- Verify the authenticity and source of any WireGuard VPN client downloads; only obtain from official WireGuard repositories
- Be cautious of unsolicited job offers, especially those requesting software installation or system access
- Implement application whitelisting and code signing verification for critical software
- Monitor for suspicious behavior from VPN clients and network tools
- Review and revoke credentials for any systems that may have executed trojanized WireGuard instances
- Conduct forensic analysis on systems where the trojanized client may have been installed
Sources
- Sandworm hackers target IT pros with trojanized WireGuard VPN client · BleepingComputer
Cite this entry
"Sandworm hackers target IT pros with trojanized WireGuard VPN client." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed May 1, 2026; last updated August 11, 2026. https://supplychainattack.org/incident/sandworm-hackers-target-it-pros-with-trojanized-wireguard-vpn-client-39oqkh
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activecritical
ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2
ChainDrop is a self-propagating npm worm that publishes malicious versions of dozens of npm packages using stolen maintainer credentials. The worm harvests CI/CD credentials and uses an Ethereum-based dead-drop command-and-control mechanism.
ChaindropnpmOtherCompromised packageMalicious maintainerAccount takeover - containedhigh
Online ad firm Adform’s script compromised to steal cryptocurrency
Adform's advertising script was compromised in a supply-chain attack that injected cryptocurrency-stealing code. The malicious script intercepted wallet addresses copied to visitors' clipboards and replaced them with attacker-controlled addresses, affecting all websites using Adform's ad platform.
OtherCompromised package - containedcritical
Malicious code in @antv/gatsby-theme (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gatsby-theme. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - activecritical
Malicious code in @antv/gi-assets-hugegraph (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 packages, including @antv/gi-assets-hugegraph. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials via the GitHub API and establishes persistence through CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit