Fake Fortinet Sites Steal VPN Credentials in Sophisticated Phishing Attack
ID: 1d65cdce-2a8f-5cbd-beb0-1c5fa532b1f1
STIX ID: report--1d65cdce-2a8f-5cbd-beb0-1c5fa532b1f1
Feed Name: cybersecurityNews.com
Threat Score
A phishing campaign is impersonating Fortinet's VPN download portal by using a GitHub Pages landing page and referrer-based redirects to a credential-harvesting site (fortinet-vpn.com), then serving a payload from myfiles2.download. The attackers leverage SEO and AI-generated search summaries to amplify reach and evade detection; the report includes domains to block and advises verifying official fortinet.com URLs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
