logo

SEO Poisoning Targets Ivanti VPN: Credential Theft Alert

ID: bd57840d-992f-5eb5-be7f-79a258e174bc

STIX ID: report--bd57840d-992f-5eb5-be7f-79a258e174bc

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-10-14

Date Updated: 2026-05-01

...
...

This report details an SEO-poisoning campaign that lures users to look-alike Ivanti Pulse Secure download pages hosted on domains such as ivanti-pulsesecure.com and ivanti-secure-access.org, which serve a signed, trojanized MSI (Ivanti-VPN.msi, MD5 6e258deec1e176516d180d758044c019) from shopping5.shop and netml.shop; the attackers use referrer-based conditional content to show malicious pages only when accessed via Bing, helping evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.