logo

How searching for a VPN could mean handing over your work login details

ID: b6fc5de0-2a5a-5047-abe1-1e788dcf4ef0

STIX ID: report--b6fc5de0-2a5a-5047-abe1-1e788dcf4ef0

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-03-17

Date Updated: 2026-04-28

...
...

This article describes a malicious campaign in which attackers use SEO poisoning and cloned vendor pages to push a fake VPN installer (distributed via GitHub and signed with a certificate later revoked). The installer drops a malicious DLL (dwmapi.dll) that loads shellcode to execute inspector.dll, a Hyrax infostealer variant that intercepts VPN credentials and saved connections, exfiltrates them to attacker-controlled infrastructure, and allows the attacker to access corporate VPN resources while presenting plausible error messages to the victim.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.