logo

Internal IT Helpdesk Spoof Used to Steal VPN Credentials

ID: 4a4c3cee-f64c-48d7-adc1-57a0c8c24e36

STIX ID: report--4a4c3cee-f64c-48d7-adc1-57a0c8c24e36

Threat Score

65/100

Uploaded: 2026-04-13

Created by: Report Uploader

TLP:GREEN
...
...
A credential-harvesting phishing campaign on 12 April 2026 targeted remote employees by spoofing helpdesk@internal-vpn-support.com and linking to a fake VPN login (https://vpn-auth-check.com/login) to collect corporate credentials and one-time codes; investigators later observed VPN access from 188.214.128.31 using a legitimate employee's credentials.