Fake VPN clients distributed through poisoned search results
Microsoft describes a campaign by the threat actor Storm-2561 that uses search engine poisoning to distribute fake VPN clients. Users searching for legitimate enterprise VPN software are steered to convincing copies of vendor websites. The downloads, often hosted on GitHub, are digitally signed trojans posing as genuine installers that steal VPN credentials.
What this means for your business
The attack hits the employee doing exactly what they should: getting the tool they need to reach the corporate network. The search ranking, the branding and the code signature are all signals people have been trained to trust. Stolen VPN credentials give the attacker a door that looks like an entirely ordinary login in your logs.
Berigo recommends
- Distribute VPN clients and other client software through your own software portal, so nobody has reason to search for installers.
- Require multi-factor authentication on VPN access so stolen credentials alone are not enough.
- Use application control that permits execution based on approved publishers, not merely on a file being signed.
- Add this scenario to security training: source criticism applies to search results and download pages too.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch