• News/
  • https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-trojanized-netextender-stealing-vpn-logins/

SonicWall warns of trojanized NetExtender stealing VPN logins

BleepingComputer
·
Bill Toulas
·
Published Jun 24, 2025
·
Updated

SonicWall is warning customers that threat actors are distributing a trojanized version of its NetExtender SSL VPN client used to steal VPN credentials. The fake software, which was discovered by SonicWall's and Microsoft Threat Intelligence (MSTIC) researchers, mimics the legitimate NetExtender v10.3.2.27, the latest available version. The malicious installer file is hosted on a spoofed website that is made to appear authentic, tricking visitors into thinking they are downloading software from SonicWall. Although the installer file is not digitally signed by SonicWall, it is signed by "CITYLIGHT MEDIA PRIVATE LIMITED," allowing it to bypass elementary defenses. The goal of the trojanized application is to steal VPN configuration and account credentials and exfiltrate them to the attacker. SonicWall NetExtender is a remote access VPN client that allows users to securely connect to their organization's internal network from remote locations. It is specifically designed to work with SonicWall SSL VPN appliances and firewalls, and it's typically used by remote staff of small to medium businesses, IT administrators, and contractors across a broad spectrum of industry types. SonicWall and Microsoft found two modified binaries of their product distributed by the malicious spoofed sites. A modified NeService.exe with its validation logic patched to bypass digital certificate checks and the NetExtender.exe file, which was modified to steal data. "Additional code was added to send VP...

Read full article

Affected Software

1 affected component
SonicWall NetExtender=10.3.2.27

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses SonicWall's warning about a trojanized version of its NetExtender SSL VPN client that is being used to steal VPN credentials.

2

What security implications are discussed in the article?

The article highlights the risk of compromised VPN logins due to the distribution of the malicious NetExtender client.

3

What products or software are affected by this issue?

The affected software is SonicWall's NetExtender SSL VPN client, specifically version 10.3.2.27.

4

Who discovered the trojanized software?

The trojanized NetExtender was discovered by security researchers from SonicWall and Microsoft Threat Intelligence.

5

What should users of SonicWall NetExtender do in response to this threat?

Users should ensure they download NetExtender only from official sources and consider updating their software to mitigate risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203