Search, Click, Steal: The Hidden Threat of Spoofed Ivanti VPN Client Sites
released on 2025-10-15 @ 04:09:27 AM
A recent campaign employs SEO poisoning on Bing to distribute a trojanized Ivanti Pulse Secure VPN client. Attackers use lookalike domains to host fake download pages, tricking users into installing a malicious MSI file. The trojan targets the connectionstore.dat file to steal VPN credentials, which are then exfiltrated to a C2 server on Azure infrastructure. This technique has been linked to Akira ransomware deployments in the past. The attack leverages signed executables and referrer-based conditional content delivery to evade detection. Organizations are advised to implement MFA, educate users, and monitor for suspicious activities to mitigate risks.