Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • PM Modi in Manipur
  • Charlie Kirk killer
  • Sushila Karki
  • IND vs PAK
  • India-US ties
  • New human organ
  • Downton Abbey: The Grand Finale Movie Review
fp-logo
Think VPNs give users safe passage? Hackers are now attacking rogue VPN servers to spread malware
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • Think VPNs give users safe passage? Hackers are now attacking rogue VPN servers to spread malware

Think VPNs give users safe passage? Hackers are now attacking rogue VPN servers to spread malware

FP Staff • November 28, 2024, 10:08:57 IST
Whatsapp Facebook Twitter

Using phishing techniques and social engineering, attackers tricked users into connecting to rogue VPN servers under their control. Malicious websites and cleverly disguised documents served as bait, convincing victims to establish connections that would compromise their systems

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
Think VPNs give users safe passage? Hackers are now attacking rogue VPN servers to spread malware
AmberWolf identified the security flaws and dubbed them "NachoVPN." AmberWolf also developed an open-source tool, aptly named NachoVPN, to simulate the attack. The tool not only demonstrates how the vulnerabilities work but also serves as a resource for researchers to identify additional security gaps. Image Credit: Pexels

The sense of security offered by VPNs might not be as foolproof as it seems. Cybersecurity experts are now warning that hackers have turned their focus to compromised VPN servers, using them to steal sensitive information from unsuspecting users.  

This alarming trend underscores the vulnerabilities lurking within widely used VPN clients. Earlier this year, researchers at AmberWolf discovered that criminals were targeting popular VPN clients like SonicWall NetExtender and Palo Alto Networks GlobalProtect.

STORY CONTINUES BELOW THIS AD

How hackers lure users into the trap

Using phishing techniques and social engineering, attackers tricked users into connecting to rogue VPN servers under their control. Malicious websites and cleverly disguised documents served as bait, convincing victims to establish connections that would ultimately compromise their systems.

Once connected, users unknowingly handed over access to their VPN clients, allowing attackers to impersonate trusted servers. This opened the door to a range of malicious activities, including the theft of login credentials, installation of malware, and even executing arbitrary code with elevated privileges. The root of the problem lay in certain VPN clients failing to properly authenticate the legitimacy of the servers they connected to.

More from Tech
How ChatGPT is becoming everyone’s BFF and why that’s dangerous How ChatGPT is becoming everyone’s BFF and why that’s dangerous America ready for self-driving cars, but it has a legal problem America ready for self-driving cars, but it has a legal problem

Vulnerabilities exposed

AmberWolf identified the security flaws and dubbed them “NachoVPN.” These vulnerabilities were reported to SonicWall and Palo Alto Networks, prompting swift action. The flaws were officially tracked as CVE-2024-29014 for SonicWall and CVE-2024-5921 for Palo Alto Networks. SonicWall patched the issue in July 2024, with the first secure version of NetExtender for Windows being 10.2.341. Palo Alto Networks followed suit in November 2024, advising users to upgrade to GlobalProtect 6.2.6 or activate FIPS-CC mode for enhanced protection.

AmberWolf also developed an open-source tool, aptly named NachoVPN, to simulate the attack. The tool not only demonstrates how the vulnerabilities work but also serves as a resource for researchers to identify additional security gaps. It supports various VPN clients, including Cisco AnyConnect, Ivanti Connect Secure, and the affected SonicWall and Palo Alto clients.

How to stay safe

The NachoVPN tool highlights the evolving threat landscape where even trusted security solutions can become attack vectors. AmberWolf emphasised that the tool is platform-agnostic and adaptable, encouraging the cybersecurity community to collaborate in addressing emerging vulnerabilities.

For users, this incident is a stark reminder to stay vigilant. Regular updates to VPN software and cautious behaviour online are essential to avoid falling victim to such sophisticated attacks. As hackers get more creative, staying ahead of threats requires both technological defences and user awareness.

Editor’s Picks
1
Fake wedding invitations shared over WhatsApp, emails are Indian scammers' favourite new tool
Fake wedding invitations shared over WhatsApp, emails are Indian scammers' favourite new tool
2
Microsoft urges Donald Trump to take tougher stance against cyberattacks from Russia, China, Iran
Microsoft urges Donald Trump to take tougher stance against cyberattacks from Russia, China, Iran
Tags
cybersecurity
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Impact Shorts

America ready for self-driving cars, but it has a legal problem

America ready for self-driving cars, but it has a legal problem

US self-driving cars may soon ditch windshield wipers as the NHTSA plans to update regulations by 2026. State-level rules vary, complicating nationwide deployment. Liability and insurance models are also evolving with the technology.

More Impact Shorts

Top Stories

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV