Fake Fortinet Sites Steal VPN Credentials in Sophisticated Phishing Attack
A recent phishing campaign has emerged, targeting remote workers and IT administrators by mimicking the official Fortinet VPN download portal. This campaign is particularly concerning due to its use of search engine optimization (SEO) and AI-generated…
A recent phishing campaign has emerged, targeting remote workers and IT administrators by mimicking the official Fortinet VPN download portal. This campaign is particularly concerning due to its use of search engine optimization (SEO) and AI-generated search summaries to deceive users.
The campaign employs a multi-stage redirection process, starting from trusted domains to bypass initial security filters, ultimately aiming to steal VPN credentials and distribute malware.
The attack leverages modern search engines, which use AI-generated summaries, to mislead users searching for "How to download Fortinet VPN." Some AI summaries mistakenly present content from the attacker’s malicious GitHub repository as legitimate instructions.
Initial links are hosted on GitHub, a reputable platform, increasing the likelihood of AI models and users trusting the source. This misplaced trust leads users to click the link, initiating the malicious activity.
The Decoy Landing: Users click a link to vpn-fortinet[.]github[.]io , which checks the referrer to filter users. Selective Redirects: If the user arrives from a major search engine, they are redirected to the phishing site fortinet-vpn[.]com . Direct visitors or security crawlers may not trigger the redirect, masking the malicious intent. Credential Harvesting: The site mimics Fortinet's design, prompting users to enter credentials before downloading the installer.
The Bait: After credentials are submitted, a download from myfiles2[.]download is initiated. The payload often includes a legitimate FortiClient version, keeping the victim unaware of the compromise.
A recent phishing campaign has emerged, targeting remote workers and IT administrators by mimicking the official Fortinet VPN download portal.
IT administrators should block the following domains and monitor internal traffic for contact with them.
IoC Type Value Description
Redirect Domain vpn-fortinet[.]github[.]io Initial landing page hosted on GitHub Pages.
Phishing URL fortinet-vpn[.]com Site where credential harvesting occurs.
Payload Host myfiles2[.]download Domain for decoy or malware payload.
Organizations should educate employees that legitimate software downloads typically do not require pre-authentication credentials. Authenticity should be confirmed by verifying the URL as the official fortinet.com domain.
This campaign underscores the need for caution with AI-generated search summaries. These tools, while convenient, can be manipulated by threat actors using basic SEO tactics. Always verify the source link before clicking.
Based on reporting by Cyber Security News.
