Attackers are hosting counterfeit X-VPN setup files that silently drop a credential-stealing remote access trojan while the VPN installs normally.
Security researchers identified trojanized X-VPN installers distributing STX RAT, a malware strain built to harvest stored credentials and maintain persistent access to compromised machines. The installer completes without obvious errors — the VPN works — while the RAT runs quietly in the background. X-VPN's own infrastructure was not breached; only files pulled from attacker-controlled servers carry the payload. Victims typically arrive there through phishing links, shady download aggregators, or search ads pointing to lookalike domains.
The target demographic makes this attack unusually efficient. People downloading VPN software are already thinking about security, which means they're more likely to hand an installer elevated permissions without a second look. VPN clients also occupy a privileged network position, making them natural candidates for credential interception. The technique sidesteps the obvious sanity check: X-VPN's official site looks clean, so a quick glance at the vendor's page won't flag the threat.
This playbook — clone a legitimate installer, stand up a plausible host, wait for downloads — has been run against nearly every major VPN brand at some point. It keeps working because the defense is friction-heavy: download only from official vendor sites, and verify checksums when they're offered.
