• News/
  • https://www.theregister.com/2025/06/24/unknown_crims_using_hacked_sonicwall/

Beware of fake SonicWall VPN app that steals users' credentials

The Register
·
Jessica Lyons
·
Published Jun 24, 2025
·
Updated

Unknown miscreants are distributing a fake SonicWall app to steal users' VPN credentials. In a Monday threat intel alert, the firewall and VPN slinger said it and Microsoft spotted the info-stealing campaign, in which would-be thieves distributed a "hacked and modified version of SonicWall's SSL VPN NetExtender application that closely resembles the official SonicWall NetExtender software." The attackers distributed a Trojanized installer of SonicWall's legitimate NetExtender 10.3.2.27, digitally signed with a fake "CITYLIGHT MEDIA PRIVATE LIMITED" certificate, via spoofed download sites. Users would visit the spoofed sites, and then download what they believed to be the most recent version of the SonicWall VPN app. But in reality, they got a fake NetExtender that, when executed, stole all their information related to the VPN configuration — username, password, domain, and more — and sent it to an attacker-controlled remote server. SonicWall did not immediately respond to The Register's inquiries about the campaign's perpetrators, its scope, or the number of users affected. But we do know that everyone from suspected Chinese spies to ransomware criminals loves to break into SonicWall devices. And, assuming they were successful with this credential-stealing scam, they wouldn't even have to break in - they'd simply log in using real names and passwords. The info-stealing application contains two modified files, both of which are part of the NetExtender installer, to execute the...

Read full article

Affected Software

1 affected component
SonicWall NetExtender=10.3.2.27

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a threat where unknown criminals are distributing a fake SonicWall VPN app designed to steal user credentials.

2

What security implications are discussed in the article?

The article highlights the risk of credential theft from users who download the counterfeit SonicWall NetExtender VPN application.

3

What products or software are affected by this security issue?

The affected product mentioned is SonicWall NetExtender, specifically version 10.3.2.27.

4

How are users being targeted by the fake app?

Users are being targeted through a phishing campaign that promotes the malicious SonicWall VPN application.

5

What actions should users take to protect themselves from this threat?

Users should avoid downloading any VPN applications from untrusted sources and verify the authenticity of software before installation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203