Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Malicious Ivanti VPN Client Sites in Google Search Deliver Malware — Users Warned

Cybersecurity researchers at Zscaler have identified a malware campaign exploiting search engine optimization (SEO) poisoning to distribute a trojanized version of the Ivanti Pulse Secure VPN client. This campaign targets users seeking legitimate…

Cybersecurity researchers at Zscaler have identified a malware campaign exploiting search engine optimization (SEO) poisoning to distribute a trojanized version of the Ivanti Pulse Secure VPN client. This campaign targets users seeking legitimate software downloads by manipulating search engine results.

The Zscaler Threat Hunting team has observed an increase in malicious activities leveraging SEO manipulation, specifically targeting Bing search engine users. Cybercriminals are deploying lookalike domains and fake download pages to steal VPN credentials, providing unauthorized access to corporate networks.

Users searching for terms like "Ivanti Pulse Secure Download" may encounter poisoned search results. These results lead to fraudulent domains such as ivanti-pulsesecure[.]com and ivanti-secure-access[.]org, which closely mimic legitimate Ivanti sites. These fake websites host replicas of the official download page, initiating the download of a trojanized MSI installer file when the download button is clicked.

The malicious file is digitally signed, which helps it evade security detection. At the time of analysis, only 2 of 58 antivirus vendors on VirusTotal flagged the installer, indicating the campaign's capability to bypass traditional security measures.

This campaign employs referrer-based conditional content delivery, dynamically adjusting displayed content based on access method. Direct visits to these domains show benign content, while access via Bing search results reveals the full phishing content.

The malicious MSI installer, signed by Hefei Qiangwei Network Technology Co., Ltd., contains credential-stealing DLLs that extract VPN server URIs and credentials from the Ivanti Pulse Secure connection storage file. The malware connects to a command-and-control server hosted on Microsoft Azure infrastructure.

This attack method is similar to campaigns associated with Akira ransomware deployment. VPN credential theft facilitates unauthorized network access, enabling further reconnaissance and potential ransomware attacks. Organizations should implement multi-factor authentication and monitor for suspicious connections.

Type Indicator

This campaign targets users seeking legitimate software downloads by manipulating search engine results.
Iris Emerson · Thehackingpost

MD5 6e258deec1e176516d180d758044c019

32a5dc3d82d381a63a383bf10dc3e337

Filename Ivanti-VPN.msi

IP Address 4[.]239[.]95[.]1

Domains netml[.]shop

shopping5[.]shop

Advertisement

ivanti-pulsesecure[.]com

ivanti-secure-access[.]org

URLs netml[.]shop/get?q=ivanti

shopping5[.]shop/?file=ivanti

C2 Path /income_shit

This campaign highlights the critical need for continuous threat hunting and proactive security measures, as even digitally signed software and top search results require scrutiny.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories