logo

Ongoing Widespread Credential Harvesting Campaign Targets VPN Providers

ID: f80adb4a-0577-51dc-a238-fe2dc919c585

STIX ID: report--f80adb4a-0577-51dc-a238-fe2dc919c585

Feed Name: WatchGuard Secplicity Blog

Threat Score
75/100

Date Published: 2026-01-13

Date Updated: 2026-05-01

Author: Ryan Estes

...
...

This report documents an active, widespread SEO‑poisoning campaign that spins up doppelganger domains for numerous VPN and remote‑access products to serve trojanized installers which capture credentials and transmit them to attacker C2 infrastructure; the report includes IoCs (domains, IPs, hashes, GitHub repos), packet captures, and a malicious code‑signing certificate, and warns the credentials may be used by ransomware affiliates while recommending mitigations such as MFA and obtaining installers directly from vendor sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.