Storm-2561 Uses Fake Fortinet, Ivanti VPN Sites to Drop Hyrax Infostealer
ID: 3f17b383-5a7f-5379-9e3e-849568be46f2
STIX ID: report--3f17b383-5a7f-5379-9e3e-849568be46f2
Feed Name: HackRead
Threat Score
Microsoft Defender Experts observed a campaign in mid-January 2026 by a group dubbed Storm-2561 that used SEO poisoning to surface realistic fake VPN download sites (e.g., vpn-fortinet.com, ivanti-vpn.org) hosting signed malicious installers on GitHub; the installers deploy a Hyrax infostealer that places files in legitimate-looking locations, prompts for credentials, and exfiltrates stolen data while showing fake errors to hide the compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
