Borrowed Trust: How Moscow Turns Everyday Software Into an Access Network- 296
August 5, 2026
A fake job offer, a hijacked hotel Wi-Fi login, a criminal marketplace listing, and an advertising plug-in buried inside a mobile app — none of these looks like state tradecraft, and that is precisely why each one works. Four cases surfacing in close succession show Russian state and state-adjacent actors converging on the same insight: rather than building bespoke infiltration tools from scratch, it is faster and more durable to compromise the software people already trust — the VPN client a sysadmin installs for a job interview, the Wi-Fi portal a business traveler logs into without thinking, the initial-access market where any criminal can shop, and the SDK a developer never audited. Each vector offers Moscow the same long-run advantage: access that looks, on the surface, like ordinary technology behaving normally.
The most deliberate example of this borrowed-trust approach comes from Ukraine's Computer Emergency Response Team, which has documented a recruitment-themed campaign run by UAC-0145, assessed as a sub-cluster of the Russian military intelligence group Sandworm (APT44). Since at least May, the group has been trawling job sites for the résumés of IT professionals and systems administrators, then reaching out directly while posing as recruiters or IT firms. Conversations move to Telegram, and candidates are walked through a video interview conducted in English over Zoom, culminating in a "technical assignment" that requires connecting to a corporate VPN. In one documented case, the attackers impersonated the international IT firm Sopra Steria using email addresses styled to resemble the company's Bulgarian office, then sent configuration files for a WireGuard VPN client alongside the mock assignment. The provided file is built to throw a fake connection error, at which point the victim is directed to download a modified WireGuard-based client called "SopraVPN" from SourceForge — a page that even links to a lookalike domain, soprasteria-bg[.]com, to reinforce the impersonation, despite having no real connection to the company. The trojanized client carries a nonstandard "SymmetricKey" configuration option that decrypts and executes embedded PowerShell code: on Windows, this creates a scheduled task and pulls down a further payload; on Linux, it uses cURL to retrieve an executable through the VPN tunnel itself. CERT-UA notes a further layer of tradecraft — the malicious build replaces WireGuard's standard Base64 decoding with a custom, dynamically generated alphabet, which renders key strings unreadable to conventional analysis tools and shields the embedded PowerShell from casual inspection. The target selection is not incidental: by aiming at the IT staff and administrators who hold the keys to telecom and enterprise networks, Sandworm converts a single successful social-engineering pitch into a foothold with outsized reach, which is why CERT-UA's guidance to telecom and IT firms is correspondingly blunt — restrict corporate resource access to managed, continuously monitored devices, including for staff working from personal equipment.
Where Sandworm subverts a specific piece of trusted software, a campaign that Microsoft has now formally attributed to the SVR-linked Midnight Blizzard group shows the same philosophy applied to shared infrastructure that millions of travelers use without a second thought. Security firm ReliaQuest first flagged the activity roughly a week earlier, after noticing that hackers had altered the DNS configurations of compromised small-office/home-office routers serving public Wi-Fi captive portals — the login pages at hotels, conference centers, and similar venues — to redirect users toward attacker-controlled infrastructure. Microsoft has since attributed the campaign, dubbed CaptiveCrunch, to Storm-2945, a subgroup of Midnight Blizzard (also tracked as APT29, Cozy Bear, and the Dukes), assessed as working on behalf of Russia's Foreign Intelligence Service. Since May, the group has been manipulating DNS and HTTP traffic across captive-portal networks, likely through access gained somewhere within the shared services that support that ecosystem, to serve Golang-based Windows remote-access trojans disguised as ordinary browser updates — malware capable of reconnaissance, credential and session-token theft, file and keystroke logging, audio and video surveillance, and remote shell access. The group has paired this with ClickFix-style social engineering to induce downloads, including a parallel push to get Android users to install a malicious APK, and has deployed additional tools tracked as the CornFlake RAT and the ChocoShell PowerShell-based infostealer, managed through a web-based command-and-control panel called FruitStone. Microsoft's most notable finding is procedural rather than technical: in the past two weeks, CaptiveCrunch landing pages have begun directing victims into device-code authentication flows, prompting them to enter an attacker-supplied code into a legitimate Microsoft sign-in page — a technique Midnight Blizzard has used since August 2024, now folded into captive-portal manipulation specifically because a login prompt encountered on ostensibly familiar Wi-Fi feels more legitimate to a tired traveler than the same prompt appearing out of nowhere. The victim profile — financial services, professional services, legal, healthcare, energy, and retail-sector employees traveling internationally, plus the IT services providers, NGOs, and government and diplomatic targets Midnight Blizzard has long pursued — reflects an intelligence-gathering mandate rather than a smash-and-grab, consistent with the group's established purpose of supporting Russian foreign-policy interests over the long term.
A third case, investigated by CloudSEK, shows how thoroughly the line between Russian cybercrime and Russian state interest can blur once access itself becomes the product being sold. Researchers identified a Russian-speaking operator running a high-volume initial-access broker operation after finding an exposed server containing a detailed record of the actor's own work. The operator's method was industrial in scale: scanning across more than a dozen countries for exposed security appliances and public-facing applications, then staging exploits for at least twelve vulnerabilities in widely deployed products from Fortinet, F5, SonicWall, Sophos, Citrix, SAP, Roundcube, vBulletin, and Hikvision, largely using public proof-of-concept code with some modifications of its own. Once inside a network, the operator used web shells and tunnels to reach Windows systems, harvested NTLM password hashes for remote authentication, and pulled credential stores, security-account data, and browser secrets to expand its foothold; in confirmed cases, it extracted the cryptographic key needed to forge long-lived Kerberos tickets, indicating complete compromise of the victim's Active Directory environment. Organizations breached this way were later named by unrelated ransomware groups, supporting CloudSEK's assessment that the operator functioned as a supplier rather than an extortionist in its own right — education, healthcare, financial services, telecommunications, and government targets across more than a dozen countries all fed the same access pipeline. What sets this case apart from ordinary cybercrime is where the operation went next: rather than continuing to sell broad commercial access, the actor pivoted to focused collection against Ukrainian defense and aerospace organizations, deploying Sliver command-and-control tooling, reaching into exposed source-code repositories, and gathering material that did not fit the pattern of routine access resale — including hundreds of images pulled from internet-facing IP cameras and screenshots captured from exposed remote-desktop sessions, offering visibility into facilities, staff movement, and logistics tied to Ukrainian critical infrastructure. That pattern echoes separate warnings about Russian-linked actors targeting cameras near border crossings and transport routes specifically to track aid shipments into Ukraine, and CloudSEK assessed with moderate-to-high confidence that the Ukraine-focused phase served state intelligence needs, while stopping short of confirming whether the operator worked under direct tasking or simply found a ready buyer for what it had already collected. Either way, the criminal and espionage phases ran on the same infrastructure, the same tunnels, and the same tooling — a single access pipeline capable of serving a ransomware crew one month and a state intelligence requirement the next.
The fourth vector requires no intrusion at all, only patience with software distribution channels that are already trusted by default. The Purdue-led study of Android applications used by US military personnel — the same study that identified Huawei's footprint in the China-focused half of this picture — also found Yandex advertising software embedded in applications used by military-affiliated users, introduced through the same kind of third-party SDK dependency that developers routinely fail to audit. The study also revisits a precedent that shows exactly how long this kind of exposure can persist once it takes root: Pushwoosh, a Russian software company that had previously presented itself publicly as a US-based business, saw its code embedded in official mobile applications operated by the US Army and the Centers for Disease Control and Prevention, a fact Reuters first reported in 2022. Both organizations removed the software once the Russian origin became public, but the episode had already run for years inside government-operated apps before anyone caught it — a reminder that this vector does not need a phishing email, a compromised router, or a stolen credential. It only needs a developer somewhere down the dependency chain who never had reason to ask where the code actually came from.
