SEO Poisoning Targets Ivanti VPN: Credential Theft Alert
ID: bd57840d-992f-5eb5-be7f-79a258e174bc
STIX ID: report--bd57840d-992f-5eb5-be7f-79a258e174bc
Feed Name: Zscaler Security Research Blog
Threat Score
This report details an SEO-poisoning campaign that lures users to look-alike Ivanti Pulse Secure download pages hosted on domains such as ivanti-pulsesecure.com and ivanti-secure-access.org, which serve a signed, trojanized MSI (Ivanti-VPN.msi, MD5 6e258deec1e176516d180d758044c019) from shopping5.shop and netml.shop; the attackers use referrer-based conditional content to show malicious pages only when accessed via Bing, helping evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
