Malicious Ivanti VPN Client Sites in Google Search Deliver Malware — Users Warned
Cybersecurity researchers at Zscaler have identified a malware campaign exploiting search engine optimization (SEO) poisoning to distribute a trojanized version of the Ivanti Pulse Secure VPN client. This campaign targets users seeking legitimate…
Cybersecurity researchers at Zscaler have identified a malware campaign exploiting search engine optimization (SEO) poisoning to distribute a trojanized version of the Ivanti Pulse Secure VPN client. This campaign targets users seeking legitimate software downloads by manipulating search engine results.
The Zscaler Threat Hunting team has observed an increase in malicious activities leveraging SEO manipulation, specifically targeting Bing search engine users. Cybercriminals are deploying lookalike domains and fake download pages to steal VPN credentials, providing unauthorized access to corporate networks.
Users searching for terms like "Ivanti Pulse Secure Download" may encounter poisoned search results. These results lead to fraudulent domains such as ivanti-pulsesecure[.]com and ivanti-secure-access[.]org, which closely mimic legitimate Ivanti sites. These fake websites host replicas of the official download page, initiating the download of a trojanized MSI installer file when the download button is clicked.
The malicious file is digitally signed, which helps it evade security detection. At the time of analysis, only 2 of 58 antivirus vendors on VirusTotal flagged the installer, indicating the campaign's capability to bypass traditional security measures.
This campaign employs referrer-based conditional content delivery, dynamically adjusting displayed content based on access method. Direct visits to these domains show benign content, while access via Bing search results reveals the full phishing content.
The malicious MSI installer, signed by Hefei Qiangwei Network Technology Co., Ltd., contains credential-stealing DLLs that extract VPN server URIs and credentials from the Ivanti Pulse Secure connection storage file. The malware connects to a command-and-control server hosted on Microsoft Azure infrastructure.
This attack method is similar to campaigns associated with Akira ransomware deployment. VPN credential theft facilitates unauthorized network access, enabling further reconnaissance and potential ransomware attacks. Organizations should implement multi-factor authentication and monitor for suspicious connections.
Type Indicator
This campaign targets users seeking legitimate software downloads by manipulating search engine results.
MD5 6e258deec1e176516d180d758044c019
32a5dc3d82d381a63a383bf10dc3e337
Filename Ivanti-VPN.msi
IP Address 4[.]239[.]95[.]1
Domains netml[.]shop
shopping5[.]shop
ivanti-pulsesecure[.]com
ivanti-secure-access[.]org
URLs netml[.]shop/get?q=ivanti
shopping5[.]shop/?file=ivanti
C2 Path /income_shit
This campaign highlights the critical need for continuous threat hunting and proactive security measures, as even digitally signed software and top search results require scrutiny.
Based on reporting by GBHackers.
