logo

SonicWall warns of trojanized NetExtender stealing VPN logins

ID: 50899f4e-c761-583d-926a-4ec2173f0f97

STIX ID: report--50899f4e-c761-583d-926a-4ec2173f0f97

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-06-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

SonicWall and Microsoft warn that threat actors are distributing trojanized NetExtender v10.3.2.27 installers via spoofed websites and malvertising; modified binaries bypass certificate checks and exfiltrate VPN credentials and configuration data (username, password, domain, etc.) to 132.196.198.163:8080. Users are advised to download only from official SonicWall portals and scan installers with up-to-date AV tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.