logo

Provider of Malicious VPN apps Disguised as Popular Vendors

ID: fb467e9f-da42-5142-adb3-dccf9fafb747

STIX ID: report--fb467e9f-da42-5142-adb3-dccf9fafb747

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ documents a May 2021 campaign where attackers registered lookalike VPN websites (e.g., vpnnords.com) to host fake installers that deploy legitimate VPN software visibly while covertly executing obfuscated components that disable Windows Defender, decrypt embedded payloads, and load an obfuscated .NET chain culminating in process hollowing to execute the Raccoon infostealer; the report includes detailed static/dynamic analysis, MITRE ATT&CK mapping, and IOCs (file hashes, malicious domains, and dropped file paths).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.