logo

Storm-2561 Uses Fake Fortinet, Ivanti VPN Sites to Drop Hyrax Infostealer

ID: 3f17b383-5a7f-5379-9e3e-849568be46f2

STIX ID: report--3f17b383-5a7f-5379-9e3e-849568be46f2

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-03-17

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Microsoft Defender Experts observed a campaign in mid-January 2026 by a group dubbed Storm-2561 that used SEO poisoning to surface realistic fake VPN download sites (e.g., vpn-fortinet.com, ivanti-vpn.org) hosting signed malicious installers on GitHub; the installers deploy a Hyrax infostealer that places files in legitimate-looking locations, prompts for credentials, and exfiltrates stolen data while showing fake errors to hide the compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.