Close Menu
Tech News VisionTech News Vision
  • Home
  • What’s On
  • Mobile
  • Computers
  • Gadgets
  • Apps
  • Gaming
  • How To
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Trending Now

Nothing’s Ear 3 earbuds have a microphone and ‘talk’ button on their charging case

11 September 2025

Review: All-Clad Gas Pizza Oven

11 September 2025

The Finals Finally Gets a Killcam — but Not on Xbox Series S, PS4, and ‘Certain’ PC Builds

11 September 2025
Facebook X (Twitter) Instagram
  • Privacy
  • Terms
  • Advertise
  • Contact
Facebook X (Twitter) Instagram Pinterest VKontakte
Tech News VisionTech News Vision
  • Home
  • What’s On
  • Mobile
  • Computers
  • Gadgets
  • Apps
  • Gaming
  • How To
  • More
    • Web Stories
    • Global
    • Press Release
Tech News VisionTech News Vision
Home » SonicWall Says Malicious NetExtender Client Used to Steal VPN Credentials
Computers

SonicWall Says Malicious NetExtender Client Used to Steal VPN Credentials

News RoomBy News Room26 June 2025Updated:26 June 2025No Comments
Facebook Twitter Pinterest LinkedIn Tumblr Email

SonicWall has issued an advisory that informs customers that a malicious version of its SonicWall SSL VPN NetExtender app is being used to steal VPN configuration and credentials. The company warns that threat actors have modified two files used by the NetExtender VPN application, which is used by several organisations to allow remote users to securely connect to the main network. Microsoft and SonicWall have taken measures to block the spread of the modified versions of the NetExtender application.

SonicWall NetExtender VPN Application Was Digitally Signed By Threat Actors

In a security advisory issued earlier this week, SonicWall said that it detected the modified version of the NetExtender SSL VPN application in collaboration with Microsoft Threat Intelligence (MSTIC). The malicious version of the app was hosted on a website that allowed users to download the trojanised version of the latest release, version 10.3.2.27.

The NetExtender application files modified by the threat actor
Photo Credit: SonicWall

 

According to the company, the threat actors digitally signed the trojanised version of the NetExtender app, which allowed it to bypass security checks on Windows. It was signed using a digital certificate issued to “CITYLIGHT MEDIA Private LIMITED”.

If a user downloaded the fake version of the SonicWall NetExtender VPN app, it would install two modified applications, “NeService.exe” and “NetExtender.exe”. The threat actor’s changes to the NeService.exe allowed them to bypass the digital certificate checks performed when the app is loaded.

Meanwhile, the modified NetExtender.exe application would collect details about the user’s VPN configuration, including their username, password, domain, and other information. These would be sent to a remote server once the user clicked the Connect button.

SonicWall has updated its malware detection tool and will automatically block the malicious software after identifying it as GAV: Fake-NetExtender (Trojan). Microsoft’s Windows Defender software will also detect the trojanised version of the app, which is categorised as “SilentRoute” Trojan (“TrojanSpy:Win32/SilentRoute.A”)

The digital certificate used to sign the installer has also been revoked, and the companies worked to take down the websites that were being used to impersonate the NetExtended VPN application. Meanwhile, SonicWall has urged users to download the application from its website instead of using third party sources.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Apple MacBook Model With A-Series Chip, Affordable Price Tag to Launch in Early 2026: Report

12 August 2025

Flipkart Independence Day Sale 2025: Best Deals on Laptops Teased Before the Sale Begins

12 August 2025

Vivo V60 – Price in India, Specifications (12th August 2025)

12 August 2025

Apple’s MacBook Pro With M6 Chip, OLED Display Could Launch by Early 2027: Mark Gurman

11 August 2025
Editors Picks

Apple’s faster MagSafe Charger can now charge other phones at 25W

11 September 2025

The 7 Best Travel Cameras

11 September 2025

Alibaba ‘plans $3.2bn raise’ to strengthen cloud computing

11 September 2025

Ubisoft Staff Reportedly Raised Concerns About Saudi Arabia Deal for Assassin’s Creed Mirage DLC, as Company Insists it Maintains Creative Control

11 September 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Trending Now
Tech News Vision
Facebook X (Twitter) Instagram Pinterest Vimeo YouTube
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact
© 2025 Tech News Vision. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.