logo

Beware of fake SonicWall VPN app that steals users' credentials

ID: 30b00448-a0ba-590e-83c1-0e7bd474d86f

STIX ID: report--30b00448-a0ba-590e-83c1-0e7bd474d86f

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-06-24

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Unknown actors distributed a Trojanized SonicWall NetExtender 10.3.2.27 installer signed with a fake "CITYLIGHT MEDIA PRIVATE LIMITED" certificate via spoofed download sites; the attackers modified NeService.exe to bypass certificate validation and altered NetExtender.exe to steal VPN configuration data (usernames, passwords, domains, etc.) and exfiltrate it to 132.196.198.163:8080. SonicWall and Microsoft removed the malicious sites and revoked the fraudulent certificate, but attackers could recreate spoofed domains, so users should only download VPN clients from vendor-trusted sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.