How searching for a VPN could mean handing over your work login details
ID: b6fc5de0-2a5a-5047-abe1-1e788dcf4ef0
STIX ID: report--b6fc5de0-2a5a-5047-abe1-1e788dcf4ef0
Feed Name: Malwarebytes Blog
This article describes a malicious campaign in which attackers use SEO poisoning and cloned vendor pages to push a fake VPN installer (distributed via GitHub and signed with a certificate later revoked). The installer drops a malicious DLL (dwmapi.dll) that loads shellcode to execute inspector.dll, a Hyrax infostealer variant that intercepts VPN credentials and saved connections, exfiltrates them to attacker-controlled infrastructure, and allows the attacker to access corporate VPN resources while presenting plausible error messages to the victim.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
