SonicWall has alerted users about a malicious campaign distributing a compromised version of its NetExtender VPN application designed to steal user information. The campaign involved a trojanized version signed with a fake certificate, which collected VPN configuration details and sent them to remote attackers. #SonicWall #NetExtender #CitylightMedia #VPNSecurity #CyberThreats
Keypoints
- The malicious campaign distributed a modified SonicWall NetExtender version to steal user data.
- The trojanized application was digitally signed with a counterfeit certificate issued to Citylight Media Private Limited.
- Attackers altered components of the installer to bypass certificate validation and collect user information.
- The stolen data included VPN credentials such as username, password, and domain.
- SonicWall and Microsoft took steps to remove the fake sites and revoke the malicious certificate.
Read More: https://www.securityweek.com/sonicwall-warns-of-trojanized-netextender-stealing-user-information/