Malvertising campaign: TU Dresden website cloned
Cybercriminals have created a malicious malvertising campaign for Cisco AnyConnect. The tool is often used by employees to connect remotely to corporate networks, but also by universities. The malicious Google ad redirects to a cloned website of the TU Dresden. Malwarebytes' Threat Intelligence team has discovered a malvertising campaign for the VPN client Cisco AnyConnect. The campaign was set for the keyword "cisco annyconnect" in Google search and redirects victims to the trustworthy-sounding domain annyconnect-secure-clientcom. However, the download file of the supposed VPN client on the fake page contains the NetSupport RAT (Remote Access Trojan)...