SonicWall warns of trojanized NetExtender stealing VPN logins
ID: 50899f4e-c761-583d-926a-4ec2173f0f97
STIX ID: report--50899f4e-c761-583d-926a-4ec2173f0f97
Feed Name: Bleeping Computer
Threat Score
SonicWall and Microsoft warn that threat actors are distributing trojanized NetExtender v10.3.2.27 installers via spoofed websites and malvertising; modified binaries bypass certificate checks and exfiltrate VPN credentials and configuration data (username, password, domain, etc.) to 132.196.198.163:8080. Users are advised to download only from official SonicWall portals and scan installers with up-to-date AV tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
