Is your VPN stealing login details?

0
2كيلو بايت

Is your VPN stealing login details?

As an Amazon Associate, we earn from qualifying purchases and other affiliate schemes. Learn more.

Christian Cawley's Avatar

Corporate security provider SonicWall has - together with Microsoft - discovered the distribution of a fake version of its VPN. This is concerning news for anyone using this VPN, as rather than protecting your privacy as you would expect, it may in fact, be exposing you.

If downloaded in error, the VPN client steals the login credentials and other information, sending the data to the hacker's server. It's a firm reminder that it is always best to stick to providers that you'll find on our list of the best VPN services, as you know that these are safe, tried, and tested.

While this tool isn't as well known as the likes of NordVPN or ExpressVPN it is one that you might find yourself protected by at in the workplace, college, or at a healthcare provider. But even if it is useless as a gaming VPN, SonicWall is an important piece of software in certain corporate scenarios.

Consequently, this has certain implications for how you choose and use VPN software. After all, you don't want to end up using a fake VPN client that diverts your username and password into the hands of cybercriminals.

What did SonicWall do about it?

Collaborating with Microsoft (SonicWall is typically found on Windows networks), SonicWall issued an advisory note explaining how the malware stole data.

"Additional code was added to send VPN configuration information to a remote server with the IP address 132.196.198.163 over port 8080. Once the VPN configuration details are entered and the "Connect" button is clicked, the malicious code performs its own validation before sending the data to the remote server. Stolen configuration information includes the username, password, domain, and more."

How does this affect non-corporate VPN users?

On the face of it, this is a problem that the IT guys where you work, or at your uni, can sort out with some patching. While that may be the ultimate solution, the attack vector is one that should concern everyone who uses a VPN.

In short, if you're not getting your VPN client from the official website or via the approved outlet (such as the App Store, Google Play, etc.) then you risk installing a fake. As this incident has demonstrated, scammers are readily able to put up a fake website to spoof people into downloading malicious scamware.

So, if you're using a VPN, stick to official sources. If you don't, but you're thinking of keeping your connection private, choose a VPN that is designed for consumers - something like NordVPN.

If you want to use a VPN for a specific game, read our Warzone VPN guide or our Minecraft VPN guide. Both are filled with lots of useful insights and perspectives.

البحث
الأقسام
إقرأ المزيد
Technology
The noise-cancelling JBL Tune Flex 2 earbuds are down to their best price ever
Noise-cancelling earbuds deal: 40% off the JBL Tune Flex 2...
بواسطة Test Blogger7 2025-10-15 18:00:19 0 898
Technology
Splurge on a Samsung QN990F 8K TV and get an $800 projector for free
Best TV deal: Buy a Samsung TV and get a Samsung Freestyle Projector for free...
بواسطة Test Blogger7 2025-06-11 18:00:22 0 2كيلو بايت
الألعاب
Channeling OSRS, single-player MMO Erenshor's new class is absolutely perfect
Channeling OSRS, single-player MMO Erenshor's new class is absolutely perfect While I...
بواسطة Test Blogger6 2025-09-23 14:00:10 0 1كيلو بايت
Technology
A London couple tracked down their stolen Jaguar thanks to an AirTag
U.K. couple steals back stolen car after tracking it down with Apple AirTag...
بواسطة Test Blogger7 2025-06-16 17:00:19 0 2كيلو بايت
الألعاب
All Hades 2 keepsakes and effects
All Hades 2 keepsakes and effects What are the best Hades 2 keepsakes? Erebus is a tricky...
بواسطة Test Blogger6 2025-09-25 17:00:13 0 1كيلو بايت