SEO poisoning and VPN spoofing used to target anything and everything with WikiLoader malware

A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
(Image credit: Shutterstock / JLStock)

Hackers deploying the WikiLoader malware are shifting tactics, moving away from phishing and into SEO poisoning and VPN spoofing. This is according to a new report from cybersecurity researchers from Palo Alto Networks’ Unit 42, which said that the new tactics, observed a few months ago, are broadening the scope of possible victims.

In June this year, Unit 42 started tracking websites that claimed to offer GlobalProtect for download. GlobalProtect is Palo Alto Networks' VPN (Virtual Private Network) solution. It provides secure remote access for users who are outside the corporate network, ensuring that their connections to the network are secure and that their traffic is protected.

The websites were obviously fake and the products offered for download there were spoofed, and also carry a piece of malware. After creating the websites, the hackers engaged in SEO poisoning, to get the sites to rank well on search engines such as Google, or Bing.

WikiLoader

SEO poisoning is a tactic in which hackers link back to the malicious site from countless different sources, tricking the search engines into deeming the website as a credible source of information.

As a consequence, when people query for different terms (for example, a VPN service), the search engines would return the malicious site relatively high up on the results page, increasing the chances of people picking up the malware.

The malware being distributed in this campaign is called WikiLoader. Also known as WailingCrab, this multistage malware loader serves as the gatekeeper which allows malicious actors to drop additional payloads, as they see fit. As such, it is usually deployed by initial access brokers (IAB), which later sell the access to the loader to a third party, which can then do with it how it pleases.

Unit 42 primarily observed WikiLoader affecting the U.S. higher education and transportation sectors, the company said, but with SEO poisoning affecting everyone, chances are that other people will get infected, too.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
malware
Google warns of legit VPN apps being used to infect devices with malware
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
China-linked cyberespionage group PlushDaemon used South Korean VPN service to inject malware
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Cisco, ASUS, QNAP, and Synology devices hijacked to major botnet
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Huge cyber attack under way - 2.8 million IPs being used to target VPN devices
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Juniper VPN gateways targeted by stealthy "magic" malware
Latest in VPN Privacy & Security
Swiss flag with view of Geneva city, Switzerland
Secure encryption and online anonymity are now at risk in Switzerland – here's what you need to know
Demonstrators protesting against the arrest of the Mayor of Istanbul Ekrem Imamoglu block Atatürk Boulevard on March 22, 2025 in Ankara, Türkiye.
Turkey's social media ban has been lifted, but VPN usage is still high
Shape of Russia filled with Russian flag-colored internet codes on a black hacking background
A new wave of blocks in Russia targets VPN apps and Cloudflare subnets
Digital hand set location on map with two pins. AI technology in GPs, innovation delivery, map location, future transport logistic, route path concept. GPs point. New office location, change address
What does your IP address reveal about you?
A stethoscope next to a laptop on a pink background
How to check if your VPN is working
Teenager playing on a gaming PC with two monitors
Is using a VPN while gaming cheating? 5 myths you shouldn't believe about gaming with a VPN
Latest in News
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does
Nintendo Virtual Game Card
Nintendo reveals the new Virtual Game Card feature, an easier way to manage your digital Switch games
Nintendo Switch 2
The Nintendo Switch 2 pre-order date has seemingly been confirmed by Best Buy Canada – here's when you'll be able to order yours
Person printing
Microsoft’s latest Windows 11 update exorcises possessed printers that spewed out pages of random characters
Pro-Ject A1.2 in black, playing a vinyl record in a hi-fi listening room
Pro-Ject's new fully-automatic turntable could be the buy of Record Store Day 2025
Intergalactic: The Heretic Prophet
Intergalactic: The Heretic Prophet reportedly won't release until after 2026, as Neil Druckmann says that staff 'are playing it at the office' right now - but I don't think I can wait that long