CERT-UA ties fake recruiter lures to Sandworm subgroup UAC-0145, which hides PowerShell execution inside a poisoned WireGuard client.