SEO poisoning and VPN spoofing are being used to attack anything and everything with WikiLoader malware

Hackers deploying the WikiLoader malware are changing tactics, moving from phishing to SEO poisoning and VPN spoofing, according to a new report According to cybersecurity researchers at Palo Alto Networks Unit 42, the new tactics observed a few months ago expand the range of potential victims.

In June of this year, Unit 42 began monitoring websites that claimed to offer GlobalProtect for download. GlobalProtect is Palo Alto Networks’ virtual private network (VPN) solution. It provides secure remote access to users outside of the corporate network, ensuring that their connections to the network are secure and their traffic is protected.