{"id":13421,"date":"2026-08-27T08:55:00","date_gmt":"2026-08-27T05:55:00","guid":{"rendered":"https:\/\/www.withsecure.com\/?post_type=lab_item&#038;p=13421"},"modified":"2026-08-27T09:24:25","modified_gmt":"2026-08-27T06:24:25","slug":"initial-access-via-seo-poisoning","status":"publish","type":"lab_item","link":"https:\/\/www.withsecure.com\/fr\/ressources\/w-labs\/initial-access-via-seo-poisoning\/","title":{"rendered":"Stolen creds and stinging loaders: An initial access campaign via SEO poisoning"},"content":{"rendered":"<section\n    class=\"wp-block-one-column-block edwp-block js-wp-block-one-column-block wp-block-one-column-block--content-1 wp-block-one-column-block--meta-sharing layout--spacing-xxxxl-top layout--spacing-xl-bottom\"\n    >\n    <div class=\"wp-block-one-column-block__container\">\n                                                                                                                            <div class='wp-block-one-column-block__meta-sharing-grid'><div class=\"wp-component-content wp-component-content--default wp-block-one-column-block__content fade-in\">\n            <h1 class=\"wp-component-heading text--h2 wp-component-content__title\">\n    Stolen creds and stinging loaders: <span class=\"blue-text\">An initial access campaign via SEO poisoning <\/span><\/h1>                    <div class=\"wp-component-content__inner\">\n                                                    <div class=\"wp-component-content__meta\">\n                                                    <span class=\"wp-component-content__content-type\">\n                                Blog post                            <\/span>\n                                                                            <span class=\"wp-component-content__meta-categories\">\n                                                                    <span class=\"wp-component-content__meta-category\">\n                                        Endpoint Security                                    <\/span>\n                                                                    <span class=\"wp-component-content__meta-category\">\n                                        Malware                                    <\/span>\n                                                                    <span class=\"wp-component-content__meta-category\">\n                                        Ransomware                                    <\/span>\n                                                                    <span class=\"wp-component-content__meta-category\">\n                                        Threat intelligence                                    <\/span>\n                                                            <\/span>\n                                                                                                    <span class=\"wp-component-content__meta-date\">\n                                27 ao\u00fbt, 2026                            <\/span>\n                                                                    <\/div>\n                                            <\/div>\n                <\/div><section\n    class=\"wp-block-sharing-icons edwp-block wp-block-sharing-icons--disable-border wp-block-sharing-icons--content-1 wp-block-sharing-icons--disable-container wp-block-one-column-block__sharing fade-in wp-block-one-column-block__sharing fade-in\"\n    >\n    <div class=\"wp-block-sharing-icons__container\">\n        <div class=\"wp-block-sharing-icons__inner\">\n                            <p class=\"wp-block-sharing-icons__title fade-in\">\n                    Partager cette information                <\/p>\n                        <div class=\"wp-component-socials wp-component-socials--dark-mode\">\n    \n            <a href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https:\/\/www.withsecure.com\/fr\/ressources\/w-labs\/initial-access-via-seo-poisoning\/&#038;title=Stolen%20creds%20and%20stinging%20loaders:%20An%20initial%20access%20campaign%20via%20SEO%20poisoning\" target=\"_blank\" rel=\"noreferer noopener\" class=\"wp-component-socials__link\" title=\"Partager sur LinkedIn\">\n            <svg class='edwp-icon edwp-icon--xlg js-icon ' aria-hidden='true'>\n                <use xlink:href='#linkedin'><\/use>\n            <\/svg>        <\/a>\n    \n            <a href=\"http:\/\/x.com\/share?text=Stolen creds and stinging loaders: An initial access campaign via SEO poisoning&#038;url=https:\/\/www.withsecure.com\/fr\/ressources\/w-labs\/initial-access-via-seo-poisoning\/\" target=\"_blank\" rel=\"noreferer noopener\" class=\"wp-component-socials__link wp-component-socials__link--twitter\" title=\"Partager sur X (Twitter)\">\n            <svg class='edwp-icon edwp-icon--xlg js-icon ' aria-hidden='true'>\n                <use xlink:href='#x'><\/use>\n            <\/svg>        <\/a>\n    \n    \n    <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n<\/div>                                                                                <\/div>\n<\/section>\n\n\n<section\n    class=\"wp-block-one-column-block edwp-block js-wp-block-one-column-block wp-block-one-column-block--content-1 layout--spacing-xxxl-bottom\"\n    >\n    <div class=\"wp-block-one-column-block__container\">\n                                                                                                                                    <div class=\"wp-component-image__wrapper wp-block-one-column-block__image fade-in\">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"2048\" height=\"1366\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/06\/2026-05-21-WithSecure-3506.jpg.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-content-25-1 wp-component-image--fit-cover\" alt=\"Overhead view down a wooden staircase of two people working on laptops in a casual seating nook below.\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/06\/2026-05-21-WithSecure-3506.jpg.webp 2048w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/06\/2026-05-21-WithSecure-3506-300x200.jpg.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/06\/2026-05-21-WithSecure-3506-1024x683.jpg.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/06\/2026-05-21-WithSecure-3506-768x512.jpg.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/06\/2026-05-21-WithSecure-3506-1536x1025.jpg.webp 1536w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/06\/2026-05-21-WithSecure-3506-447x298.jpg.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/06\/2026-05-21-WithSecure-3506-219x146.jpg.webp 219w\" sizes=\"auto, (max-width: 2048px) 100vw, 2048px\" \/>                                                    <\/figure>\n                    <\/div>\n                                                                                <\/div>\n<\/section>\n\n\n<section\n    class=\"wp-block-two-column-block edwp-block js-wp-block-two-column-block wp-block-two-column-block--content-1 wp-block-two-column-block__left--align-y-top wp-block-two-column-block__right--align-y-top wp-block-two-column-block--split-sidebar layout--none-top layout--spacing-xxxl-bottom\"\n    data-block-id=\"block_42cd89af6d8c8dafef4257dce7e9f3e2\"\n    >\n    <div class=\"wp-block-two-column-block__container row-load\">\n                                                        <div class=\"wp-block-two-column-block__left\">\n                                    <div class=\"wp-component-authors-list wp-block-two-column-block__authors\">\n                    <p class=\"wp-component-authors-list__title\">\n                Authors            <\/p>\n        \n        <div class=\"wp-component-authors-list__items\">\n                                                <div class=\"wp-component-author-card \">\n    <div class=\"wp-component-author-card__media\">\n                    <img loading=\"lazy\" decoding=\"async\" width=\"1080\" height=\"1080\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Mohammad-Kazem-Hassan-Nejad_WithSecure_2.jpg.webp\" class=\"wp-component-author-card__photo\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Mohammad-Kazem-Hassan-Nejad_WithSecure_2.jpg.webp 1080w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Mohammad-Kazem-Hassan-Nejad_WithSecure_2-300x300.jpg.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Mohammad-Kazem-Hassan-Nejad_WithSecure_2-1024x1024.jpg.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Mohammad-Kazem-Hassan-Nejad_WithSecure_2-150x150.jpg.webp 150w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Mohammad-Kazem-Hassan-Nejad_WithSecure_2-768x768.jpg.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Mohammad-Kazem-Hassan-Nejad_WithSecure_2-447x447.jpg.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Mohammad-Kazem-Hassan-Nejad_WithSecure_2-700x700.jpg.webp 700w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/Mohammad-Kazem-Hassan-Nejad_WithSecure_2-146x146.jpg.webp 146w\" sizes=\"auto, (max-width: 1080px) 100vw, 1080px\" \/>            <\/div>\n    <div class=\"wp-component-author-card__content\">\n                    <h3 class=\"wp-component-author-card__name\">Mohammad Kazem Hassan Nejad<\/h3>\n        \n                    <p class=\"wp-component-author-card__meta\">\n                Senior Threat Intelligence Researcher, WithSecure            <\/p>\n                \n            <\/div>\n\n<\/div>\n\n                                    <\/div>\n\n            <\/div>\n<nav\n    class=\"wp-component-content-navigation wp-block-two-column-block__content-nav js-content-navigation\"\n    data-bem-base=\"wp-component-content-navigation\"\n    data-nav-column=\"left\"\n    data-nav-type=\"auto\"\n>\n            <p class=\"wp-component-content-navigation__title\">\n            Content        <\/p>\n    \n    <div class=\"wp-component-content-navigation__mobile\">\n        <label class=\"wp-component-content-navigation__mobile-label\">\n            <span class=\"wp-component-content-navigation__mobile-label-text\">\n                Navigation dans le contenu            <\/span>\n            <select class=\"wp-component-content-navigation__select js-content-navigation-select\">\n                <option value=\"\">\n                    S\u00e9lectionnez une section                <\/option>\n                            <\/select>\n        <\/label>\n    <\/div>\n\n    <div class=\"wp-component-content-navigation__desktop\">\n        <div class=\"wp-component-content-navigation__list-wrapper\">\n            <span\n                class=\"wp-component-content-navigation__indicator js-content-navigation-indicator\"\n                aria-hidden=\"true\"\n            ><\/span>\n            <ul class=\"wp-component-content-navigation__list js-content-navigation-list\">\n                            <\/ul>\n        <\/div>\n    <\/div>\n<\/nav>\n<section\n    class=\"wp-block-sharing-icons edwp-block wp-block-sharing-icons--disable-border wp-block-sharing-icons--disable-container wp-block-two-column-block__share wp-block-two-column-block__hide-mobile wp-block-two-column-block__share wp-block-two-column-block__hide-mobile\"\n    >\n    <div class=\"wp-block-sharing-icons__container\">\n        <div class=\"wp-block-sharing-icons__inner\">\n                            <p class=\"wp-block-sharing-icons__title fade-in\">\n                    Share this story                <\/p>\n                        <div class=\"wp-component-socials wp-component-socials--dark-mode\">\n    \n            <a href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https:\/\/www.withsecure.com\/fr\/ressources\/w-labs\/initial-access-via-seo-poisoning\/&#038;title=Stolen%20creds%20and%20stinging%20loaders:%20An%20initial%20access%20campaign%20via%20SEO%20poisoning\" target=\"_blank\" rel=\"noreferer noopener\" class=\"wp-component-socials__link\" title=\"Partager sur LinkedIn\">\n            <svg class='edwp-icon edwp-icon--xlg js-icon ' aria-hidden='true'>\n                <use xlink:href='#linkedin'><\/use>\n            <\/svg>        <\/a>\n    \n            <a href=\"http:\/\/x.com\/share?text=Stolen creds and stinging loaders: An initial access campaign via SEO poisoning&#038;url=https:\/\/www.withsecure.com\/fr\/ressources\/w-labs\/initial-access-via-seo-poisoning\/\" target=\"_blank\" rel=\"noreferer noopener\" class=\"wp-component-socials__link wp-component-socials__link--twitter\" title=\"Partager sur X (Twitter)\">\n            <svg class='edwp-icon edwp-icon--xlg js-icon ' aria-hidden='true'>\n                <use xlink:href='#x'><\/use>\n            <\/svg>        <\/a>\n    \n    \n    <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n                <\/div>\n                                                <div class=\"wp-block-two-column-block__right\">\n                                <div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <h2>Summary<\/h2>\n<p>WithSecure is tracking an ongoing campaign that leverages SEO poisoning with the goal of gaining initial access into victim environments. This is achieved either by phishing for corporate VPN and remote desktop credentials or by delivering initial access malware such as the Bumblebee loader. The threat actor registers domains impersonating the targeted software and applies blackhat SEO techniques to boost their visibility across search results.<\/p>\n<p>We assess that the threat actor likely operates as an Initial Access Broker (IAB) in the Ransomware-as-a-Service (RaaS) ecosystem, hence successful phishing or compromise can lead to extortion via data theft and\/or data encryption.<\/p>\n<p>WithSecure was able to trace back this campaign to earlier activity running since at least May 2025. The threat actor has previously leveraged Bumblebee loader as initial access malware and trojanized VPN software to harvest VPN credentials. Several prior reports have covered aspects of this campaign; however WithSecure discovered new and additional key findings, including:<\/p>\n<ol>\n<li>Resurgence of Bumblebee loader as initial access malware by the threat actor.<\/li>\n<li>Changes to the primary payload used by the threat actor to steal VPN credentials.<\/li>\n<li>Additional web-based phishing methods to steal VPN and remote desktop credentials.<\/li>\n<li>Insights into the blackhat SEO techniques leveraged by the threat actor.<\/li>\n<li>Indicators suggesting development by a Russian-speaking threat actor.<\/li>\n<\/ol>\n<h2>Introduction<\/h2>\n<p>In Q2 2026, WithSecure investigated several customer incidents involving the execution of a malicious HTML application (.hta) that masqueraded as a WatchGuard SSL VPN client but functioned as a VPN credential stealer.<\/p>\n<p>Upon further investigation, we discovered these HTA files were being distributed to victims via SEO poisoning. The threat actor had registered domains impersonating WatchGuard VPN software and applied black hat SEO techniques to surface them prominently across search results.<\/p>\n<p>These incidents led WithSecure to investigate the wider activity cluster and unravel a larger campaign that traces back to at least May 2025. Several prior reports have covered aspects of this activity; however, we found that:<\/p>\n<ol>\n<li>These incidents involved a new infection chain<\/li>\n<li>The breadth of targeted applications reaches well beyond VPN clients into remote desktop and enterprise software<\/li>\n<li>The threat actor also operates an additional attack chain which phishes credentials directly through web-based forms rather than file-based malware. A method that had not been detailed in available reporting.<\/li>\n<\/ol>\n<h2>Phishing for VPN credentials \u2013 Fake VPN clients<\/h2>\n<p>One of the primary objectives of the threat actor is to harvest VPN credentials that can serve as an initial access vector (IAV) into a victim\u2019s network perimeter. To this end, the threat actor has impersonated a wide array of VPN software developed by most major and niche vendors, including:<\/p>\n<ol>\n<li>WatchGuard Mobile VPN \/ Firebox SSL<\/li>\n<li>Fortinet\u2019s FortiClient<\/li>\n<li>Sophos Connect<\/li>\n<li>Check Point VPN<\/li>\n<li>Palo Alto GlobalProtect<\/li>\n<li>SonicWall NetExtender<\/li>\n<li>BIG-IP Edge Client<\/li>\n<li>NetScaler\/Citrix Gateway<\/li>\n<\/ol>\n<p>The attack chain begins when a user searching to download a VPN client clicks on one of the campaign\u2019s sites in the search engine results page (SERP) that closely mimics the vendor\u2019s legitimate download site. An example is shown in figure 1.<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"1432\" height=\"647\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_1.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_1.png.webp 1432w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_1-300x136.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_1-1024x463.png.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_1-768x347.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_1-447x202.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_1-323x146.png.webp 323w\" sizes=\"auto, (max-width: 1432px) 100vw, 1432px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 1.<\/strong> Example of user searching to download SonicWall&rsquo;s NetExtender<\/p>\n<p>&nbsp;<\/p>\n<p>Once the victim clicks to download the software on the lookalike site, they are served a malicious payload that is either hosted on legitimate third-party services, such as Dropbox or GitHub, or an attacker-controlled domain. In some instances, the threat actor uses a redirection chain to mask the main download link behind another attacker-controlled domain. The delivered payload is often bundled as an archive file (.ZIP). An example is shown in figure 2.<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"1727\" height=\"971\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_2.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_2.png.webp 1727w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_2-300x169.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_2-1024x576.png.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_2-768x432.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_2-1536x864.png.webp 1536w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_2-447x251.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_2-700x394.png.webp 700w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_2-260x146.png.webp 260w\" sizes=\"auto, (max-width: 1727px) 100vw, 1727px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 2.<\/strong> Example of fake Sophos Connect site with malicious Dropbox download link (ZIP file)<\/p>\n<p>&nbsp;<\/p>\n<p>The delivered payload has varied over time. Between May 2025 and early 2026, WithSecure mainly observed trojanized MSI installers and custom PE-based payloads that led to VPN credential theft, some of which have been documented <a href=\"https:\/\/www.sonicwall.com\/blog\/threat-actors-modify-and-re-create-commercial-software-to-steal-users-information\" target=\"_blank\" rel=\"noopener\">in<\/a> <a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/spoofed-ivanti-vpn-client-sites\" target=\"_blank\" rel=\"noopener\">the<\/a> <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/03\/12\/storm-2561-uses-seo-poisoning-to-distribute-fake-vpn-clients-for-credential-theft\/\" target=\"_blank\" rel=\"noopener\">past<\/a>.<\/p>\n<p>Since February 2026, WithSecure observed the threat actor shift away from their traditional PE-based payloads and start delivering custom HTML application (.hta) files that masqueraded as the respective VPN client.<\/p>\n<p>Once executed, the HTA file would load a highly convincing logon portal on the victim\u2019s machine that masquerades as the respective VPN client. Any VPN credentials and configuration data that are entered into the logon portal are then exfiltrated to an attacker-controlled domain. An example is shown in figure 3.<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"2126\" height=\"680\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_3.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_3.png.webp 2126w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_3-300x96.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_3-1024x328.png.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_3-768x246.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_3-1536x491.png.webp 1536w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_3-2048x655.png.webp 2048w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_3-447x143.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_3-456x146.png.webp 456w\" sizes=\"auto, (max-width: 2126px) 100vw, 2126px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 3.<\/strong> Example of HTA payload with credential theft capabilities &#8211; fake Sophos Connect logon portal<\/p>\n<p>&nbsp;<\/p>\n<p>To deceive the victim, a fake error message is displayed afterwards as decoy. An example is shown in figure 4.<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"880\" height=\"702\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_4.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_4.png.webp 880w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_4-300x239.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_4-768x613.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_4-447x357.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_4-183x146.png.webp 183w\" sizes=\"auto, (max-width: 880px) 100vw, 880px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 4.<\/strong> Example of an error message shown as decoy<\/p>\n<p>&nbsp;<\/p>\n<p>The payload dynamically fetches and renders the user interface (UI) of the fake VPN client by making an HTTP GET request to an attacker-controlled domain with a custom header \u201cX-From-HTA\u201d set as \u201cyes-hta-2025\u201d. An example code snippet is shown in figure 5.<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"861\" height=\"810\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_5-1.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_5-1.png.webp 861w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_5-1-300x282.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_5-1-768x723.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_5-1-447x421.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_5-1-155x146.png.webp 155w\" sizes=\"auto, (max-width: 861px) 100vw, 861px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 5.<\/strong> Example code snippet to dynamically fetch and render fake VPN UI<\/p>\n<p>&nbsp;<\/p>\n<p>The threat actor inserted dummy functions into the payload files to inflate their size, likely as a detection-evasion technique. An example is shown in figure 6.<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"1650\" height=\"262\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_6.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_6.png.webp 1650w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_6-300x48.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_6-1024x163.png.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_6-768x122.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_6-1536x244.png.webp 1536w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_6-447x71.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_6-919x146.png.webp 919w\" sizes=\"auto, (max-width: 1650px) 100vw, 1650px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 6.<\/strong> Dummy code inserted into HTA files<\/p>\n<p>&nbsp;<\/p>\n<p>Moreover, the threat actor leveraged an obscure <a href=\"https:\/\/www.john-am.com\/2010\/07\/building-a-self-contained-hta-with-embedded-images-and-icons\/\" target=\"_blank\" rel=\"noopener\">technique<\/a> to display the appropriate VPN application icon for each payload. Icon data was prepended to each HTA file and the HTA <a href=\"https:\/\/learn.microsoft.com\/lb-lu\/previous-versions\/ms536482(v=vs.85)\" target=\"_blank\" rel=\"noopener\">icon property<\/a> was set to \u00ab\u00a0#\u00a0\u00bb, causing mshta.exe to use the embedded icon when displaying the HTML application. Therefore, the resulting payloads are considered as <a href=\"https:\/\/en.wikipedia.org\/wiki\/Polyglot_(computing)\" target=\"_blank\" rel=\"noopener\">polygot<\/a> files, making them valid as both ICO and HTA file formats. An example is shown in figure 7.<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"1781\" height=\"875\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_7.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_7.png.webp 1781w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_7-300x147.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_7-1024x503.png.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_7-768x377.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_7-1536x755.png.webp 1536w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_7-447x220.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_7-297x146.png.webp 297w\" sizes=\"auto, (max-width: 1781px) 100vw, 1781px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 7.<\/strong> Example of polyglot payload with icon data prepended to the HTA file<\/p>\n<p>&nbsp;<\/p>\n<h2>We<span lang=\"EN-US\">b-based credential phishing<\/span><\/h2>\n<p>WithSecure identified a secondary method the threat actor employed to harvest VPN credentials using the same VPN software download lure described in the previous section. Rather than relying purely on file-based attack chains, the threat actor deployed phishing pages that harvested VPN credentials in some instances. For example, the victim would land on the download sites via SEO poisoning, but upon pressing the download link a phishing form would be overlayed, prompting the user to enter their VPN credentials. The entered VPN credentials would then be exfiltrated to an attacker-controlled domain and the legitimate software installer would be downloaded as a decoy. WithSecure identified the threat actor leveraging this technique to harvest VPN credentials for at least:<\/p>\n<ul>\n<li>NordLayer VPN<\/li>\n<li>Fortinet FortiClient<\/li>\n<li>BIG-IP Edge client<\/li>\n<li>SonicWall NetExtender<\/li>\n<li>Ivanti Secure Access<\/li>\n<li>WatchGuard VPN<\/li>\n<\/ul>\n<p>Examples of the phishing pages are shown in figures 8 and 9.<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"1644\" height=\"932\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_8.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_8.png.webp 1644w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_8-300x170.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_8-1024x581.png.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_8-768x435.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_8-1536x871.png.webp 1536w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_8-447x253.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_8-258x146.png.webp 258w\" sizes=\"auto, (max-width: 1644px) 100vw, 1644px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 8.<\/strong> Example of phishing form to harvest VPN credentials &#8211; SonicWall NetExtender<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"1646\" height=\"927\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_9.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_9.png.webp 1646w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_9-300x169.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_9-1024x577.png.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_9-768x433.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_9-1536x865.png.webp 1536w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_9-447x252.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_9-700x394.png.webp 700w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_9-259x146.png.webp 259w\" sizes=\"auto, (max-width: 1646px) 100vw, 1646px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 9.<\/strong> Example of phishing form to harvest VPN credentials &#8211; Ivanti Secure Access<\/p>\n<p>&nbsp;<\/p>\n<p>Beyond VPN credentials, WithSecure also observed the threat actor leverage phishing pages to target credentials for remote desktop software such as Microsoft\u2019s Remote Desktop Services web client (RDWeb) and Getscreen.me. In these instances, the lookalike sites acted as logon portals that would exfiltrate any entered logon credentials while showing an error message as decoy afterwards. An example is shown in figure 10.<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"1319\" height=\"933\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_10.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_10.png.webp 1319w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_10-300x212.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_10-1024x724.png.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_10-768x543.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_10-447x316.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_10-206x146.png.webp 206w\" sizes=\"auto, (max-width: 1319px) 100vw, 1319px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 10.<\/strong> Example of fake Getscreen.me logon portal exfiltrating entered credentials<\/p>\n<p>&nbsp;<\/p>\n<h2>The Bumblebee still stings<\/h2>\n<p>Several of the associated domains WithSecure found since March 2026 masqueraded as sites for software other than VPN and remote desktop applications. These included:<\/p>\n<ol>\n<li>Azure CLI<\/li>\n<li>PingPlotter<\/li>\n<li>Nx Witness<\/li>\n<li>Veeam Backup and Replication<\/li>\n<\/ol>\n<p>These lookalike sites led to Bumblebee loader infections. The threat actor has leveraged Bumblebee loader throughout their <a href=\"https:\/\/www.cyjax.com\/resources\/blog\/a-sting-on-bing-bumblebee-delivered-through-bing-seo-poisoning-campaign\" target=\"_blank\" rel=\"noopener\">earliest<\/a> traced activity, dating between the second and third quarters of 2025. All the latest identified Bumblebee payloads contained the campaign ID: \u201c1000\u201d. Historical campaign IDs included: \u201cgrp0003\u201d and \u201cgrp0004\u201d.<\/p>\n<p>For example, an associated lookalike site found in August 2026 for Veeam Backup &amp; Replication software contained a Dropbox-hosted download link. The downloaded file was a modified ISO image for the respective software, with three modified or newly added files including:<\/p>\n<ol>\n<li>Setup.exe, the original setup executable, modified to import veeamstat.dll<\/li>\n<li>veeamstat.dll, a custom loader intended to run the main payload (x64.dll) via rundll32.exe \u00ab\u00a0&lt;SetupDir&gt;\\EnterpriseManager\\x64.dll\u00a0\u00bb,DllRegisterServer<\/li>\n<li>x64.dll, VMProtect-packed Bumblebee loader<\/li>\n<\/ol>\n<p>This discovery indicates the threat actor\u2019s continued interest in targeting victims using a wide array of software within enterprise environments. Bumblebee loader infections through this campaign have been previously <a href=\"https:\/\/thedfirreport.com\/2026\/06\/29\/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3\/\" target=\"_blank\" rel=\"noopener\">reported<\/a> to lead to Akira ransomware intrusions. It is noteworthy that the Bumblebee loader was subject to an international takedown operation dubbed <a href=\"https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/largest-ever-operation-against-botnets-hits-dropper-malware-ecosystem\" target=\"_blank\" rel=\"noopener\">Operation Endgame<\/a> in May 2024, however the loader <a href=\"https:\/\/www.netskope.com\/blog\/new-bumblebee-loader-infection-chain-signals-possible-resurgence\" target=\"_blank\" rel=\"noopener\">resurfaced<\/a> several months later, albeit at nowhere near the same level of activity.<\/p>\n<h2>Getting to the frontpage<\/h2>\n<p>The threat actor employs several blackhat SEO techniques, including <a href=\"https:\/\/en.wikipedia.org\/wiki\/Cloaking\" target=\"_blank\" rel=\"noopener\">cloaking<\/a> and <a href=\"https:\/\/en.wikipedia.org\/wiki\/Link_building#Black_hat_link_building\" target=\"_blank\" rel=\"noopener\">link building<\/a>, to enhance the authenticity of the lookalike domains and boost their visibility across search results.<\/p>\n<p>As part of their cloaking scheme, the domains serve a benign SEO-friendly website (referred to as \u201cwhite page\u201d) to any request that isn\u2019t redirected from a search engine, such as search engine crawlers. Meanwhile, requests originating from a search engine are served the malicious content (referred to as \u201coffer\u201d or \u201cblack\u201d page). Incidentally, this mechanism also serves as an anti-analysis technique.<\/p>\n<p>WithSecure found an example of a custom cloaking script employed by the threat actor across some instances which filtered requests based on the visitor\u2019s browser, operating system, and the request\u2019s referrer header field, which is used to check whether the request originates from a supported search engine. An example code snippet is shown in figure 11. Notably, the list of supported search engines also contained entries for ChatGPT and Copilot to allow requests originating from these platforms. In addition to the custom cloaking script, WithSecure also found evidence of a third-party cloaking service used by the threat actor, namely cloaking[.]house.<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1638\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_11-scaled.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_11-scaled.png.webp 2560w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_11-300x192.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_11-1024x655.png.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_11-768x491.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_11-1536x983.png.webp 1536w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_11-2048x1310.png.webp 2048w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_11-447x286.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_11-228x146.png.webp 228w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 11.<\/strong> Example code snippet of cloaking script<\/p>\n<p>&nbsp;<\/p>\n<p>The content served across all the lookalike domains as white page were designed as \u201cunofficial guides\u201d related to the masqueraded software. These pages followed best SEO practices to improve their search result ranking. On the other hand, the offer (or black) pages were scraped copies of the official download pages for the respective software. An example of a white page is shown in figure 12.<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"1600\" height=\"1200\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_12.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_12.png.webp 1600w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_12-300x225.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_12-1024x768.png.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_12-768x576.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_12-1536x1152.png.webp 1536w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_12-447x335.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_12-195x146.png.webp 195w\" sizes=\"auto, (max-width: 1600px) 100vw, 1600px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 12.<\/strong> White page masquerading as an unofficial guide for WatchGuard Mobile VPN client<\/p>\n<p>&nbsp;<\/p>\n<p>WithSecure observed usage of ccTLDs (e.g. foobar.fi) across several of the identified lookalike domain names. The language used across these sites\u2019 metadata (such as the site description displayed across search engine results) as well as their white pages were in the respective country\u2019s main language. For example, French was used for domains ending with \u201c.fr\u201d. These geotargeting techniques were likely employed to expand the campaign\u2019s reach by boosting the ranking of these domains across search results in certain geographies. Nearly all identified geography-specific domains were in Europe. Despite these geotargeting techniques, WithSecure did not observe any explicit geo-fencing to these sites, indicating the targeting is global in scope. An example is shown in figure 13, where a user in Finland searching for NetExtender is served the lookalike domain netextender[.]fi among the top results. Additional examples of geotargeted search results are shown in figure 14.<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"1432\" height=\"647\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_13.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_13.png.webp 1432w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_13-300x136.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_13-1024x463.png.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_13-768x347.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_13-447x202.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_13-323x146.png.webp 323w\" sizes=\"auto, (max-width: 1432px) 100vw, 1432px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 13.<\/strong> User from Finland searching to download NetExtender<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"1920\" height=\"571\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_14-1-1.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_14-1-1.png.webp 1920w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_14-1-1-300x89.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_14-1-1-1024x305.png.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_14-1-1-768x228.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_14-1-1-1536x457.png.webp 1536w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_14-1-1-447x133.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_14-1-1-491x146.png.webp 491w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 14.<\/strong> Additional examples of geotargeted search results<\/p>\n<p>&nbsp;<\/p>\n<p>Moreover, WithSecure observed the threat actor engage in blackhat link-building practices for some of the domains. For instance, we identified several backlinks to these lookalike domains injected across sites such as Private Blog Networks (PBNs). Examples are shown in figures 15 and 16.<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                            <figure class=\"wp-component-image__figure\">\n                <img loading=\"lazy\" decoding=\"async\" width=\"1237\" height=\"1509\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_15.png.webp\" class=\"wp-component-image wp-component-image--desktop wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_15.png.webp 1237w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_15-246x300.png.webp 246w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_15-839x1024.png.webp 839w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_15-768x937.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_15-447x545.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_15-120x146.png.webp 120w\" sizes=\"auto, (max-width: 1237px) 100vw, 1237px\" \/>                            <\/figure>\n            <figure class=\"wp-component-image__figure\">\n                                    <img loading=\"lazy\" decoding=\"async\" width=\"1237\" height=\"1509\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_15.png.webp\" class=\"wp-component-image wp-component-image--mobile \n                wp-component-image--ratio-full\n             \n                wp-component-image--fit-cover\n            \" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_15.png.webp 1237w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_15-246x300.png.webp 246w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_15-839x1024.png.webp 839w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_15-768x937.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_15-447x545.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_15-120x146.png.webp 120w\" sizes=\"auto, (max-width: 1237px) 100vw, 1237px\" \/>                                            <\/figure>\n            <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 15.<\/strong> Example of backlinks across Private Blog Networks (PBNs)<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"1452\" height=\"1272\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_16.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_16.png.webp 1452w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_16-300x263.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_16-1024x897.png.webp 1024w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_16-768x673.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_16-447x392.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_16-167x146.png.webp 167w\" sizes=\"auto, (max-width: 1452px) 100vw, 1452px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 16.<\/strong> Example of backlinks injected across page sidebar and footer<\/p>\n<p>&nbsp;<\/p>\n<h2>The Russian links<\/h2>\n<p>Throughout the investigation, WithSecure repeatedly observed the use of Russian language in the form of code comments, debug messages, and filenames across artifacts found throughout the attack chain.<\/p>\n<p>For instance, some of the cloned sites\u2019 resources contained filenames appended with \u201c\u0411\u0435\u0437 \u043d\u0430\u0437\u0432\u0430\u043d\u0438\u044f\u201d (Russian word for Untitled). An example is shown in figure 17.<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"575\" height=\"663\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_17.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_17.png.webp 575w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_17-260x300.png.webp 260w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_17-447x515.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_17-127x146.png.webp 127w\" sizes=\"auto, (max-width: 575px) 100vw, 575px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 17.<\/strong> Example of Russian language used in filenames<\/p>\n<p>&nbsp;<\/p>\n<p>Some of the phishing pages contained debug messages in Russian. An example is shown in figure 18.<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"617\" height=\"296\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_18.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_18.png.webp 617w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_18-300x144.png.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_18-447x214.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_18-304x146.png.webp 304w\" sizes=\"auto, (max-width: 617px) 100vw, 617px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 18.<\/strong> Example of Russian language used in debug messages across phishing pages<\/p>\n<p>&nbsp;<\/p>\n<p>We also identified code comments in Russian across the HTA infection chains. An example is shown in figure 19.<\/p>\n<\/div>\n        <div class=\"wp-component-image__wrapper wp-block-two-column-block__image \">\n                    <figure class=\"wp-component-image__figure\">\n                                            <img loading=\"lazy\" decoding=\"async\" width=\"768\" height=\"1204\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_19.png.webp\" class=\"wp-component-image\n                            wp-component-image--desktop\n                            wp-component-image--mobile\n                            wp-component-image--ratio-full wp-component-image--fit-cover\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_19.png.webp 768w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_19-191x300.png.webp 191w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_19-653x1024.png.webp 653w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_19-447x701.png.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/08\/figure_19-93x146.png.webp 93w\" sizes=\"auto, (max-width: 768px) 100vw, 768px\" \/>                                                    <\/figure>\n                    <\/div>\n<div class=\"wp-component-paragraph wp-block-two-column-block__paragraph \">\n    <p><strong>Figure 19.<\/strong> Example of code comments across HTA infection chain<\/p>\n<p>&nbsp;<\/p>\n<p>These indicators suggest development by a Russian-speaking threat actor, potentially hinting towards the threat actor\u2019s origin or cybercrime ecosystem they operate within.<\/p>\n<h2>Conclusion<\/h2>\n<p>SEO poisoning remains a popular initial attack vector amongst threat actors. With the goal of establishing an initial foothold in a victim\u2019s corporate environment, this campaign focuses on software such as VPN clients that are used in enterprise environments. By masquerading as trusted software and poisoning relevant search engine results, the threat actor hinges on the abuse of trust to lure users to malicious sites that can lead to credential phishing or malware delivery.<\/p>\n<p>The consequences extend well beyond that initial compromise. We assess the threat actor likely operates as an Initial Access Broker within the Ransomware-as-a-Service ecosystem. A single employee downloading what appears to be a legitimate VPN client can therefore expose an organization to extortion via data theft, data encryption, or both.<\/p>\n<p>The threat actor\u2019s multi-pronged approach and broader software impersonation reflect an opportunistic threat actor that leverages any means necessary to gain initial access into organizations in an indiscriminate fashion. This is reflected by their shift from PE-based payloads to polyglot HTA credential stealers, a parallel web-based phishing chain, the expansion from VPN clients into remote desktop and wider enterprise software, and the resurgence of Bumblebee loader behind increasingly mature blackhat SEO tradecraft.<\/p>\n<p>We suspect that the threat actor will continue leveraging this method for initial access, likely modifying parts of their tradecraft, such as delivered payloads and infrastructure, to further evade detection. However, by driving user awareness against these campaigns, their employed methods may become less effective over time, imposing a cost by forcing threat actors to adapt.<\/p>\n<p>A full list of Indicators of Compromise (IOCs) and relevant YARA rules can be found in WithSecure\u2019s GitHub [ <a href=\"https:\/\/github.com\/WithSecureLabs\/iocs\/tree\/master\/Initial_Access_SEO_Poisoning\/\" target=\"_blank\" rel=\"noopener\">https:\/\/github.com\/WithSecureLabs\/iocs\/tree\/master\/Initial_Access_SEO_Poisoning\/<\/a> ].<\/p>\n<h2>Recommendations<\/h2>\n<ul>\n<li>Rotate potentially exposed VPN and remote desktop credentials immediately if compromise is assessed or suspected.<\/li>\n<li>Invest in Endpoint Protection, Detection and Response (EPP\/EDR) solutions with network and file reputation coverage, as well as behavioral coverage for abuse of living-off-the-land binaries such as mshta.exe and rundll32.exe, and ensure alerts are triaged and actioned promptly.<\/li>\n<li>Restrict execution of HTML applications by blocking or limiting mshta.exe through application control solutions (e.g. AppLocker or WDAC) based on business needs and treat internet-downloaded container formats such as ISO images with heightened scrutiny.<\/li>\n<li>Enforce multi-factor authentication (MFA) for VPN, remote desktop, and other remote access services, preferring phishing-resistant methods such as FIDO2 or certificate-based authentication so that stolen credentials alone are insufficient to gain access.<\/li>\n<li>Ensure minimum privilege for VPN and remote desktop accounts and segment the network to limit the reach of a compromised account, reducing the value of harvested credentials to an Initial Access Broker and their customers.<\/li>\n<li>Drive user training and awareness to download software only from official vendor sites or an internal software portal rather than trusting top search results, noting that this campaign also accommodates traffic originating from AI assistants such as ChatGPT and Copilot.<\/li>\n<li>Distribute VPN clients and other enterprise software through managed channels, such as an internal software catalogue or endpoint management tooling, removing the need for users to search the web for installers.<\/li>\n<li>Leverage the published IOCs and YARA rules to hunt for related activity across endpoint and network telemetry.<\/li>\n<\/ul>\n<h2>WithSecure&rsquo;s detection coverage<\/h2>\n<p>WithSecure\u2122 Elements Endpoint Protection and WithSecure\u2122 Elements Detection and Response offer detection and protection across various stages of the attack lifecycle.<\/p>\n<p>WithSecure\u2122 Elements Endpoint Protection detections include:<\/p>\n<ul>\n<li>Trojan:HTA\/Hermes.A<\/li>\n<li>Trojan.TR\/W64.MalwareX<\/li>\n<\/ul>\n<p>WithSecure\u2122 Elements Endpoint Detection and Response detections include:<\/p>\n<ul>\n<li>Suspicious Mshta Location<\/li>\n<li>Network Mshta<\/li>\n<\/ul>\n<h2><span lang=\"EN-US\">MITRE ATT&amp;CK mapping<\/span><\/h2>\n<table style=\"width: 100%; border-collapse: collapse;\" border=\"1\">\n<tbody>\n<tr>\n<td style=\"width: 33.3333%;\">Name<\/td>\n<td style=\"width: 33.3333%;\">ID<\/td>\n<td style=\"width: 33.3333%;\">Description<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Acquire Infrastructure: Domains<\/td>\n<td style=\"width: 33.3333%;\">T1583.001<\/td>\n<td style=\"width: 33.3333%;\">The threat actor registered lookalike domains impersonating VPN, remote desktop, and enterprise software, including geotargeted ccTLD domains (e.g. netextender[.]fi).<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Acquire Infrastructure: Web Services<\/td>\n<td style=\"width: 33.3333%;\">T1583.006<\/td>\n<td style=\"width: 33.3333%;\">The threat actor leveraged legitimate third-party services, such as Dropbox and GitHub, to host malicious payloads.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Stage Capabilities: Upload Malware<\/td>\n<td style=\"width: 33.3333%;\">T1608.001<\/td>\n<td style=\"width: 33.3333%;\">Malicious payloads were staged on attacker-controlled domains and legitimate file-hosting services, in some cases masked behind a redirection chain.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Stage Capabilities: SEO Poisoning<\/td>\n<td style=\"width: 33.3333%;\">T1608.006<\/td>\n<td style=\"width: 33.3333%;\">The threat actor applied blackhat SEO techniques to boost the lookalike domains across search results, including SEO-friendly white pages, cloaking (custom scripts and the third-party service cloaking[.]house), backlink injection across Private Blog Networks (PBNs), and geotargeting.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Drive-by Compromise<\/td>\n<td style=\"width: 33.3333%;\">T1189<\/td>\n<td style=\"width: 33.3333%;\">Users searching to download software were lured via poisoned search results to lookalike sites serving credential phishing pages or malware.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">User Execution: Malicious File<\/td>\n<td style=\"width: 33.3333%;\">T1204.002<\/td>\n<td style=\"width: 33.3333%;\">Infection required victims to download and execute the served payloads (e.g. HTA files, trojanized MSI installers, modified ISO images).<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">System Binary Proxy Execution: Mshta<\/td>\n<td style=\"width: 33.3333%;\">T1218.005<\/td>\n<td style=\"width: 33.3333%;\">HTA-based credential stealers were executed via mshta.exe.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">System Binary Proxy Execution: Rundll32<\/td>\n<td style=\"width: 33.3333%;\">T1218.011<\/td>\n<td style=\"width: 33.3333%;\">Bumblebee loader (x64.dll) was executed via rundll32.exe using the DllRegisterServer export.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Hijack Execution Flow: DLL<\/td>\n<td style=\"width: 33.3333%;\">T1574.001<\/td>\n<td style=\"width: 33.3333%;\">The original Setup.exe in the trojanized Veeam Backup &amp; Replication ISO image was modified to import the custom loader veeamstat.dll.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Masquerading: Match Legitimate Resource Name or Location<\/td>\n<td style=\"width: 33.3333%;\">T1036.005<\/td>\n<td style=\"width: 33.3333%;\">Payloads and lookalike domains masqueraded as legitimate VPN, remote desktop, and enterprise software and their vendors&rsquo; download sites.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Masquerading: Masquerade File Type<\/td>\n<td style=\"width: 33.3333%;\">T1036.008<\/td>\n<td style=\"width: 33.3333%;\">Icon data was prepended to the HTA payloads, creating ICO\/HTA polyglot files that display the impersonated VPN client&rsquo;s icon when rendered by mshta.exe.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Obfuscated Files or Information: Binary Padding<\/td>\n<td style=\"width: 33.3333%;\">T1027.001<\/td>\n<td style=\"width: 33.3333%;\">Dummy functions were inserted into the HTA payloads to inflate their size, likely as a detection-evasion technique.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Obfuscated Files or Information: Software Packing<\/td>\n<td style=\"width: 33.3333%;\">T1027.002<\/td>\n<td style=\"width: 33.3333%;\">The Bumblebee loader payload (x64.dll) was packed with VMProtect.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Input Capture: GUI Input Capture<\/td>\n<td style=\"width: 33.3333%;\">T1056.002<\/td>\n<td style=\"width: 33.3333%;\">Fake logon portals rendered on the victim&rsquo;s machine by the HTA payloads or served as web-based phishing forms captured credentials entered by victims, displaying a fake error message as decoy.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Application Layer Protocol: Web Protocols<\/td>\n<td style=\"width: 33.3333%;\">T1071.001<\/td>\n<td style=\"width: 33.3333%;\">The HTA payloads dynamically fetched the fake VPN client UI over HTTP from an attacker-controlled domain using the custom header \u201cX-From-HTA: yes-hta-2025\u201d.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Exfiltration Over C2 Channel<\/td>\n<td style=\"width: 33.3333%;\">T1041<\/td>\n<td style=\"width: 33.3333%;\">Captured VPN and remote desktop credentials and configuration data were exfiltrated to attacker-controlled domains.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">External Remote Services<\/td>\n<td style=\"width: 33.3333%;\">T1133<\/td>\n<td style=\"width: 33.3333%;\">Harvested VPN and remote desktop credentials likely serve as an initial access vector (IAV) into victims&rsquo; network perimeters.<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.3333%;\">Valid Accounts<\/td>\n<td style=\"width: 33.3333%;\">T1078<\/td>\n<td style=\"width: 33.3333%;\">Assessed: operating as an Initial Access Broker, the actor likely uses or sells stolen credentials to enable follow-on intrusions, including ransomware operations.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<section\n    class=\"wp-block-sharing-icons edwp-block wp-block-sharing-icons--disable-border wp-block-sharing-icons--disable-container wp-block-two-column-block__share wp-block-two-column-block__mobile-after-right wp-block-two-column-block__share wp-block-two-column-block__mobile-after-right\"\n    >\n    <div class=\"wp-block-sharing-icons__container\">\n        <div class=\"wp-block-sharing-icons__inner\">\n                            <p class=\"wp-block-sharing-icons__title fade-in\">\n                    Share this story                <\/p>\n                        <div class=\"wp-component-socials wp-component-socials--dark-mode\">\n    \n            <a href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https:\/\/www.withsecure.com\/fr\/ressources\/w-labs\/initial-access-via-seo-poisoning\/&#038;title=Stolen%20creds%20and%20stinging%20loaders:%20An%20initial%20access%20campaign%20via%20SEO%20poisoning\" target=\"_blank\" rel=\"noreferer noopener\" class=\"wp-component-socials__link\" title=\"Partager sur LinkedIn\">\n            <svg class='edwp-icon edwp-icon--xlg js-icon ' aria-hidden='true'>\n                <use xlink:href='#linkedin'><\/use>\n            <\/svg>        <\/a>\n    \n            <a href=\"http:\/\/x.com\/share?text=Stolen creds and stinging loaders: An initial access campaign via SEO poisoning&#038;url=https:\/\/www.withsecure.com\/fr\/ressources\/w-labs\/initial-access-via-seo-poisoning\/\" target=\"_blank\" rel=\"noreferer noopener\" class=\"wp-component-socials__link wp-component-socials__link--twitter\" title=\"Partager sur X (Twitter)\">\n            <svg class='edwp-icon edwp-icon--xlg js-icon ' aria-hidden='true'>\n                <use xlink:href='#x'><\/use>\n            <\/svg>        <\/a>\n    \n    \n    <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n                <\/div>\n                        <\/div>\n<\/section>\n\n\n<section\n    class=\"wp-block-cta-banner edwp-block js-wp-block-cta-banner wp-block-cta-banner--style-icon wp-block-cta-banner--no-image layout--spacing-xxxl-top layout--spacing-xxxl-bottom\"\n    >\n    <div class=\"wp-block-cta-banner__container\">\n        <div class=\"wp-block-cta-banner__box row-load\">\n            <div class=\"wp-component-content wp-component-content--help-text wp-component-content--dark wp-block-cta-banner__content\">\n                        <div class=\"wp-component-content__inner\">\n                <h2 class=\"wp-component-heading text--h2 wp-component-heading--dark wp-component-content__title\">\n    What <span class=\"blue-text\">next?<\/span><\/h2>                                    <div class=\"wp-component-content__content wysiwyg wysiwyg--dark\">\n                        <div class=\"wp-component-paragraph wp-component-paragraph--dark\">\n    <p class=\"text--p-medium\">Discover WithSecure\u2122 Elements Exposure Management.<br \/>\n&#8211; No credit card required. No obligations.No complexity.<\/p>\n<\/div>\n                    <\/div>\n                            <\/div>\n                            <div class=\"wp-component-content__buttons\">\n                <a class=\"wp-component-button btn btn--primary btn--dark\" href=\"https:\/\/www.withsecure.com\/en\/contact-us\/\">Contact us<\/a>            <\/div>\n                <\/div>                    <\/div>\n    <\/div>\n<\/section>\n\n\n\n\n<section\n    class=\"wp-block-cards edwp-block wp-block-cards--col-3 layout--spacing-xxxl-top layout--spacing-xxxl-bottom\"\n    >\n    <div class=\"wp-block-cards__container\">\n        <div class=\"wp-component-content wp-component-content--default wp-block-cards__content\">\n            <h2 class=\"wp-component-heading text--h2 wp-component-content__title\">\n    Contenus associ\u00e9s<\/h2>                    <div class=\"wp-component-content__inner\">\n                                    <div class=\"wp-component-content__content wysiwyg\">\n                        <div class=\"wp-component-paragraph \">\n    <p><span data-teams=\"true\">D\u00e9couvrez d&rsquo;autres contenus en rapport avec ce sujet.<\/span><\/p>\n<\/div>\n                    <\/div>\n                                                            <\/div>\n                <\/div>                                            <div class=\"wp-block-cards__cards row-load\">\n                    <div class=\"wp-component-card-insight wp-block-cards__card wp-component-card-insight--highlighted\">\n    <div class=\"wp-component-card-insight__image-wrapper\">\n        <img loading=\"lazy\" decoding=\"async\" width=\"618\" height=\"440\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/placeholder.jpg.webp\" class=\"wp-component-card-insight__image\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/placeholder.jpg.webp 618w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/placeholder-300x214.jpg.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/placeholder-447x318.jpg.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/placeholder-205x146.jpg.webp 205w\" sizes=\"auto, (max-width: 618px) 100vw, 618px\" \/>                    <p class=\"wp-component-card-insight__content-type\">Blog post<\/p>\n            <\/div>\n    <div class=\"wp-component-card-insight__content\">\n                    <div class=\"wp-component-card-insight__meta\">\n                <div class=\"wp-component-card-insight__categories\">\n                                            <span class=\"wp-component-card-insight__category\">Endpoint Security<\/span>\n                                            <span class=\"wp-component-card-insight__category\">Malware<\/span>\n                                            <span class=\"wp-component-card-insight__category\">Ransomware<\/span>\n                                            <span class=\"wp-component-card-insight__category\">Threat intelligence<\/span>\n                                    <\/div>\n            <\/div>\n                            <h3 class=\"wp-component-card-insight__title\">Stolen creds and stinging loaders: An initial access campaign via SEO poisoning<\/h3>\n                                                    <div class=\"wp-component-card-insight__button-wrapper\">\n                <a class=\"wp-component-button btn btn--primary btn--dark wp-component-card-insight__button btn--small\" href=\"https:\/\/www.withsecure.com\/fr\/ressources\/w-labs\/initial-access-via-seo-poisoning\/\">En savoir plus<\/a>            <\/div>\n            <\/div>\n<\/div><div class=\"wp-component-card-insight wp-block-cards__card\">\n    <div class=\"wp-component-card-insight__image-wrapper\">\n        <img loading=\"lazy\" decoding=\"async\" width=\"618\" height=\"440\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/placeholder.jpg.webp\" class=\"wp-component-card-insight__image\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/placeholder.jpg.webp 618w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/placeholder-300x214.jpg.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/placeholder-447x318.jpg.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/placeholder-205x146.jpg.webp 205w\" sizes=\"auto, (max-width: 618px) 100vw, 618px\" \/>                    <p class=\"wp-component-card-insight__content-type\">Publications<\/p>\n            <\/div>\n    <div class=\"wp-component-card-insight__content\">\n                    <div class=\"wp-component-card-insight__meta\">\n                <div class=\"wp-component-card-insight__categories\">\n                                            <span class=\"wp-component-card-insight__category\">AI security<\/span>\n                                            <span class=\"wp-component-card-insight__category\">Software Protection<\/span>\n                                            <span class=\"wp-component-card-insight__category\">Threat intelligence<\/span>\n                                    <\/div>\n            <\/div>\n                            <h3 class=\"wp-component-card-insight__title\">GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations<\/h3>\n                                                    <div class=\"wp-component-card-insight__button-wrapper\">\n                <a class=\"wp-component-button btn btn--primary wp-component-card-insight__button btn--small\" href=\"https:\/\/www.withsecure.com\/fr\/ressources\/w-labs\/greyvibe\/\">En savoir plus<\/a>            <\/div>\n            <\/div>\n<\/div><div class=\"wp-component-card-insight wp-block-cards__card\">\n    <div class=\"wp-component-card-insight__image-wrapper\">\n        <img loading=\"lazy\" decoding=\"async\" width=\"618\" height=\"440\" src=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/placeholder.jpg.webp\" class=\"wp-component-card-insight__image\" alt=\"\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/placeholder.jpg.webp 618w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/placeholder-300x214.jpg.webp 300w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/placeholder-447x318.jpg.webp 447w, https:\/\/www.withsecure.com\/wp-content\/smush-webp\/2026\/05\/placeholder-205x146.jpg.webp 205w\" sizes=\"auto, (max-width: 618px) 100vw, 618px\" \/>                    <p class=\"wp-component-card-insight__content-type\">Blog post<\/p>\n            <\/div>\n    <div class=\"wp-component-card-insight__content\">\n                    <div class=\"wp-component-card-insight__meta\">\n                <div class=\"wp-component-card-insight__categories\">\n                                            <span class=\"wp-component-card-insight__category\">Attack Detection<\/span>\n                                            <span class=\"wp-component-card-insight__category\">Software Protection<\/span>\n                                            <span class=\"wp-component-card-insight__category\">Threat intelligence<\/span>\n                                    <\/div>\n            <\/div>\n                            <h3 class=\"wp-component-card-insight__title\">DarkGate Rises: New version of DarkGate malware hunts like a Duck but bites like a RAT<\/h3>\n                                            <p class=\"wp-component-card-insight__desc\">Source: https:\/\/labs.withsecure.com\/publications\/darkgate-rises<\/p>\n                            <div class=\"wp-component-card-insight__button-wrapper\">\n                <a class=\"wp-component-button btn btn--primary wp-component-card-insight__button btn--small\" href=\"https:\/\/www.withsecure.com\/fr\/ressources\/w-labs\/darkgate-rises\/\">En savoir plus<\/a>            <\/div>\n            <\/div>\n<\/div>                <\/div>\n                                                <\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":20,"featured_media":0,"template":"","categories":[328,179,214,308],"labs_content_type":[309],"class_list":["post-13421","lab_item","type-lab_item","status-publish","hentry","category-endpoint-security","category-malware","category-ransomware","category-threat-intelligence"],"acf":[],"card":"<div class=\"wp-component-card-insight js-card-link wp-component-card-insight--highlighted\">\n    <div class=\"wp-component-card-insight__image-wrapper\">\n        <img width=\"618\" height=\"440\" src=\"https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/05\/placeholder.jpg\" class=\"wp-component-card-insight__image\" alt=\"\" decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/05\/placeholder.jpg 618w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/05\/placeholder-300x214.jpg 300w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/05\/placeholder-447x318.jpg 447w, https:\/\/www.withsecure.com\/wp-content\/uploads\/2026\/05\/placeholder-205x146.jpg 205w\" sizes=\"auto, (max-width: 618px) 100vw, 618px\" \/>                    <p class=\"wp-component-card-insight__content-type\">Blog post<\/p>\n            <\/div>\n    <div class=\"wp-component-card-insight__content\">\n                    <div class=\"wp-component-card-insight__meta\">\n                <div class=\"wp-component-card-insight__categories\">\n                                            <span class=\"wp-component-card-insight__category\">Endpoint Security<\/span>\n                                            <span class=\"wp-component-card-insight__category\">Malware<\/span>\n                                            <span class=\"wp-component-card-insight__category\">Ransomware<\/span>\n                                            <span class=\"wp-component-card-insight__category\">Threat intelligence<\/span>\n                                    <\/div>\n            <\/div>\n                            <h3 class=\"wp-component-card-insight__title\">Stolen creds and stinging loaders: An initial access campaign via SEO poisoning<\/h3>\n                                                    <div class=\"wp-component-card-insight__button-wrapper\">\n                <a class=\"wp-component-button btn btn--primary btn--dark wp-component-card-insight__button btn--small\" href=\"https:\/\/www.withsecure.com\/fr\/ressources\/w-labs\/initial-access-via-seo-poisoning\/\">En savoir plus<\/a>            <\/div>\n            <\/div>\n<\/div>","_links":{"self":[{"href":"https:\/\/www.withsecure.com\/fr\/wp-json\/wp\/v2\/lab_item\/13421","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.withsecure.com\/fr\/wp-json\/wp\/v2\/lab_item"}],"about":[{"href":"https:\/\/www.withsecure.com\/fr\/wp-json\/wp\/v2\/types\/lab_item"}],"author":[{"embeddable":true,"href":"https:\/\/www.withsecure.com\/fr\/wp-json\/wp\/v2\/users\/20"}],"wp:attachment":[{"href":"https:\/\/www.withsecure.com\/fr\/wp-json\/wp\/v2\/media?parent=13421"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.withsecure.com\/fr\/wp-json\/wp\/v2\/categories?post=13421"},{"taxonomy":"labs_content_type","embeddable":true,"href":"https:\/\/www.withsecure.com\/fr\/wp-json\/wp\/v2\/labs_content_type?post=13421"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}