A counterfeit SonicWall NetExtender installer was used to steal VPN configuration data. The incident involved an attacker-operated download site, not a reported compromise of SonicWall’s official download infrastructure. SonicWall and Microsoft identified the campaign in June 2025.
What happened
Attackers distributed a modified copy of SonicWall’s SSL VPN client, NetExtender, to people searching for the legitimate application. The reported sample was version 10.3.2.27 and carried a digital signature from CITYLIGHT MEDIA PRIVATE LIMITED. Reporting noted a similarly named company, but did not establish any connection between that company and the operation.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
SonicWall TZ470 Network Security/Firewall Appliance | $825.30 | Buy on Amazon |
| 2 |
|
SonicWall TZ270W Wireless Gen7 Firewall | SMB Wi-Fi Security Appliance with 2 Gbps Firewall Speed,... | $468.00 | Buy on Amazon |
| 3 |
|
Sonicwall NSA 2700 (02-SSC-4324) | $2,159.20 | Buy on Amazon |
SonicWall told Dark Reading that no SonicWall subdomain was used in the campaign. The delivery site was controlled by the attackers, so this was a malicious-download and credential-theft incident rather than an established vulnerability in the genuine NetExtender application.
How the counterfeit installer worked
Modified installer components
Investigators found changes in two binaries:
- NeService.exe: patched to bypass digital certificate validation.
- NetExtender.exe: fitted with code that collected VPN configuration information and transmitted it after the victim entered details and clicked Connect.
Data sent to the remote server
The reported sample sent usernames, passwords, domains and other VPN configuration data to 132.196.198.163 over port 8080. SonicWall senior principal engineer Sravan Ganachari described the behavior as code added to the installed binaries so that VPN configuration information was stolen and sent to a remote server.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- The latest SonicWall TZ470 series, are the first desktop form factor nextgeneration firewalls (NGFW) with 1 or 5 Gigabit Ethernet interfaces. The series consist of a wide range of products to suit a variety of use cases.
- Reduce complexity and get the business running without relying on IT personnel with easy onboarding using SonicExpress App and Zero-Touch Deployment, and easy management through a single pane of glass
- Drive business growth by investing in next-gen appliances with multi-gigabit and advanced security features, to future-proof against the changing network and security landscape
- Ensure seamless communication as stores talk to HQ via easy VPN connectivity which allows IT administrators to create a hub and spoke configuration for the safe transport of data between all locations
- Hardware: Operating system: SonicOS 7. | Interfaces: 8x1GbE, 2x1GbE, 2 USB 3., 1 Console | Management: Network Security Manager, CLI, SSH, Web UI, GMS, REST APIs | VLAN interfaces: 128 | Access points supported (maximum): 32
What this means for NetExtender users
The presence of a digital signature did not make the file trustworthy. The signer identified in the report was not SonicWall, and the installer came from an attacker-controlled site. A signed file must still be checked for publisher identity, download provenance and approval by your organization.
How to download the real SonicWall client
SonicWall’s advice, as quoted in the June 2025 reporting, is: “It is strongly recommended that users download SonicWall applications only from trusted sources: sonicwall.com or mysonicwall.com.”
Rank #2
- SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
- Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
- Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
- Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
- Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.
- Start at sonicwall.com or your organization’s approved SonicWall portal.
- If your administrator directs you to mysonicwall.com, verify that the browser address is exactly that domain before downloading.
- Use your company’s software-distribution process when one is provided; do not substitute a search-result download or an unofficial mirror.
- Before running an installer, check its publisher and signature. A signature from an unrelated publisher is a reason to stop and contact your security team.
What SonicWall and Microsoft did
The June 2025 report said SonicWall and Microsoft Threat Intelligence worked to mitigate the campaign. Relevant websites were taken down, and the installer’s certificate was revoked. The report also named detections from SonicWall Capture ATP with RTDMI, SonicWall Managed Security Services and Microsoft Defender. Those statements describe the reported response in June 2025; they are not a guarantee of current detection coverage.
If you may have installed the fake client
The published account does not provide a complete, vendor-specific remediation checklist. Treat a suspected installation as a potential credential exposure and follow your organization’s incident-response process.
Rank #3
- The SonicWall Network Security appliance (NSa) Mid-Range Firewall is next-generation security designed specifically for businesses of 250 users and up.
- Secure Remote Workers - SonicWall NetExtender provides an intuitive SSL-VPN connection client that’s easy to deploy and configure. Easily provide your remote workers with secure access to your corporate network from Linux, Mac and Windows devices.
- Built-in Wireless Controller - Implement high-speed wireless security by combining a NSa Series next-generation firewall with a SonicWall SonicWave wireless access point. NSa Series firewalls and SonicWave access points both feature 2.5 GbE ports that enable multi-gigabit wireless throughput offered in Wave 2 wireless technology.
- With cloud-based and on-box capabilities like TLS/SSL decryption and inspection, application intelligence and control, secure SD-WAN, real-time visualization, and WLAN management, SonicWall provides flexible, fast and cost-effective security to keep the threats out and your business thriving.
- Highlights: 1 RU – Form Factor | 16 x 1 GbE interfaces | 3 x 10 GbE interfaces | 2 Gbps Threat and Malware Analysis Throughput | Enterprise Internet Edge Ready
- Contact your security or IT team immediately and preserve the installer, host details and relevant logs if your policy allows.
- Ask the security team whether the computer should be isolated from the network while it is examined.
- Discuss rotating VPN passwords and other credentials that may have been entered, using the organization’s approved process.
- Have the host checked for the reported binaries, unexpected network connections and other signs of compromise.
- Do not reinstall a client from the same search result or third-party site; obtain replacement software through SonicWall’s official domains or your managed deployment system.
What is not established
The reporting did not identify the threat actor, provide a victim count or quantify the number of affected installations. SonicWall said it had no information to share about the actor’s identity at that time. Dark Reading also reported SonicWall’s understanding that other enterprise software packages may have been altered similarly, but that was an unconfirmed scope statement, not proof that any named vendor was affected.
Quick Recap
Key facts at a glance
| Item | Reported detail |
|---|---|
| Incident type | Counterfeit NetExtender installer from an attacker-operated site |
| Reported version | 10.3.2.27 |
| Digital signer | CITYLIGHT MEDIA PRIVATE LIMITED; relationship to the attacker was not established |
| Altered files | NeService.exe and NetExtender.exe |
| Reported stolen data | Username, password, domain and other VPN configuration information |
| Destination | 132.196.198.163 over port 8080 |
| Official download guidance | Use sonicwall.com or mysonicwall.com |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

