SonicWall warns of trojanized NetExtender stealing VPN logins
Customers are being alerted by SonicWall that threat actors are disseminating a trojanized version of its NetExtender SSL VPN client, which is used to steal VPN credentials.
Researchers from SonicWall and Microsoft Threat Intelligence (MSTIC) found the fraudulent programme, which imitates the most recent version of NetExtender, v10.3.2.27.
By posing as an official website, the malicious installation file deceives users into believing they are installing software from SonicWall. Despite not being digitally signed by SonicWall, the installer file is signed by "CITYLIGHT MEDIA PRIVATE LIMITED," which enables it to get past basic security measures.
The trojanized application aims to exfiltrate account credentials and VPN configuration to the attacker.
With the help of the remote a...

