logo

Storm-2561 lures victims to spoofed VPN sites to harvest corporate logins

ID: 77ce9086-0471-569b-868c-b5c565972016

STIX ID: report--77ce9086-0471-569b-868c-b5c565972016

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-03-14

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Microsoft reported that Storm-2561 has run an active credential-theft campaign since May 2025 that uses SEO-poisoned search results to redirect users seeking legitimate VPN clients (Ivanti, Cisco, Fortinet/Pulse Secure) to spoofed vendor pages hosting trojanized ZIP/MSI installers. The installers, signed with a now-revoked certificate, side-load malicious DLLs and deploy the Hyrax infostealer to harvest VPN credentials and related connection data (exfiltrating to attacker-controlled infrastructure), then present a fake error and redirect victims to the real vendor to hide the compromise; Microsoft published IoCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.