```html ```
top of page

We Aimed Our New Hunter at the Fortune 500 and Found Fake Citrix, Cisco, and Fortinet Installers — Impersonating the VPN Clients Your IT Admins Use to Reach the Corporate Network.

  • Writer: Patrick Duggan
    Patrick Duggan
  • Jul 16
  • 4 min read

Updated: Aug 11

Yesterday we built a hunter that finds fake-installer GitHub repositories by behavior, off the back of Arctic Wolf's report on a 292-repo campaign impersonating trusted software. Today we pointed it at a Fortune 500 brand list to answer a simple question: does the impersonation surface reach past crypto wallets and consumer apps into the enterprise? It does, and the cluster it surfaced is the one worth your attention.


The consumer hits were the expected ones — fake QuickBooks, TurboTax, Norton, McAfee, Adobe Acrobat, all fresh, all wearing the same tell. Those matter. But they are not the ones that made me stop. The ones that made me stop were the fake enterprise remote-access clients.



What We Found


In a single 24-brand Fortune 500 sweep, the hunter flagged, as high-confidence blocks, impersonation repositories for the exact software an IT department downloads to connect people to the corporate network. Five separate fake Citrix Workspace organizations. A fake Cisco Secure Client. A fake Fortinet FortiClient. A fake Palo Alto GlobalProtect. A fake VMware desktop client. Every one of them used the same pattern the Arctic Wolf campaign used — a freshly created GitHub organization whose only content is a slick .github landing page with a download button, zero stars, zero forks, days to weeks old.


These are not the crown jewels of one company. They are the crown jewels of the category. A fake crypto wallet steals one person's coins. A fake corporate VPN client is something else entirely, because of who installs it and what it connects to.



Why This Cluster Is Worse Than the Wallets


Think about the delivery path. Somebody — an employee told to "install the VPN to work from home," or worse, an IT admin standing up remote access for a team — searches for their company's VPN client. An SEO-boosted fake repository, wearing the real vendor's name and a convincing landing page, is waiting in the results. They download what they believe is Citrix Workspace or FortiClient or GlobalProtect. What they actually run is a trojanized installer, and the thing that installer does first is harvest credentials.


Now walk the consequence. The credential it steals is not a gaming login. It is a corporate credential, often one attached to the remote-access path itself. We have spent this entire year writing that the edge appliance — the SonicWall, the Cisco ASA, the Citrix gateway, the Fortinet box — is the initial-access surface of the era, the door ransomware crews pay bulletproof hosts to reach. This is the client-side version of that same door. You do not have to burn a zero-day in the appliance if you can convince the person with legitimate access to install your malware while they are trying to install the real client. Same destination, cheaper ticket.


That is the through-line worth naming: attackers are working both ends of enterprise remote access at once. The appliance gets exploited from outside; the client gets impersonated from the front. A defense that only watches the appliance is watching one side of a door that opens both ways.



Our Receipt, and the Honest Limits


We did not read about these in someone else's report. Our hunter found them today, and they are now written into our own indicator feed as brand-impersonation repositories, which means anyone pulling that feed inherits the catch and can block or report them. The detection is behavioral, not name-based — the org-stage pattern, the freshness, the throwaway shape, a README that routes off GitHub to a download. We flag on what the repository does, not on the fact that it contains the word "Citrix."


And we cap the confidence honestly at the usual ninety-five percent. The hunter produces a scored, prioritized queue; a human should confirm each before filing a formal abuse report, because the occasional legitimate community mirror lives in the long tail and a fake that has already been abandoned is less urgent than one still serving. What we will say without hedging is that a freshly minted GitHub organization offering you a "Fortinet FortiClient download" through a link that leaves GitHub has no legitimate reason to exist, and there were more of them than we expected.



What To Do


The rule is boring and it is the whole defense: get enterprise client software from the vendor's own domain, full stop. Not from a GitHub repository, not from a search result that looks official, not from a link a colleague pasted. If your organization distributes VPN or remote-access clients internally, distribute them from a path your people are trained to trust, so that a convincing fake in a search result has nothing to compete with. And treat a GitHub org whose entire existence is a download button for a named enterprise product as hostile until proven otherwise — because the tell that catches these at scale is not the brand in the name, it is the shape of the thing wearing it.


We built the hunter yesterday. Today it found fake versions of the software that connects companies to themselves. Tomorrow it runs against the whole roster, on a schedule, so the next batch is caught while it is still empty.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=we-aimed-our-new-hunter-at-the-fortune-500-and-found-fake-citrix-cisco-and-fortinet-installers-i



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page