Ongoing Widespread Credential Harvesting Campaign Targets VPN Providers
ID: f80adb4a-0577-51dc-a238-fe2dc919c585
STIX ID: report--f80adb4a-0577-51dc-a238-fe2dc919c585
Feed Name: WatchGuard Secplicity Blog
This report documents an active, widespread SEO‑poisoning campaign that spins up doppelganger domains for numerous VPN and remote‑access products to serve trojanized installers which capture credentials and transmit them to attacker C2 infrastructure; the report includes IoCs (domains, IPs, hashes, GitHub repos), packet captures, and a malicious code‑signing certificate, and warns the credentials may be used by ransomware affiliates while recommending mitigations such as MFA and obtaining installers directly from vendor sites.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
