logo

Credential-stealing crew spoofs VPN clients from Cisco, Fortinet, and others

ID: 34ff2242-a49c-5759-8ce4-57994f0473bc

STIX ID: report--34ff2242-a49c-5759-8ce4-57994f0473bc

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2026-03-13

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Microsoft warns that the Storm-2561 criminal group is running an active campaign that pushes spoofed enterprise VPN installers (MSI) to the top of search results; these installers sideload malicious DLLs, present fake sign-in prompts to capture credentials, exfiltrate them to attacker-controlled C2 servers, and then display an installation failure while directing victims to the legitimate vendor site. The report includes IOCs (malicious domains and signed-but-revoked certificate details) and vendor-neutral mitigations such as enforcing MFA and avoiding storing workplace credentials in personal browser/password vaults.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.