logo

Cyberattackers Spoof Palo Alto VPNs to Spread WikiLoader Variant

ID: 3c936b58-be28-5869-99ed-7cc2108feed1

STIX ID: report--3c936b58-be28-5869-99ed-7cc2108feed1

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-09-03

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Researchers observed a campaign using SEO poisoning to promote spoofed GlobalProtect VPN download pages that deliver a new variant of the WikiLoader (WailingCrab) downloader. Discovered by Palo Alto Unit 42 in June, the campaign leverages phishing and compromised WordPress sites, targets US higher education and transportation sectors and organizations in Italy, and uses trusted-software spoofing to help bypass endpoint controls and allowlisting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.