logo

Fake enterprise VPN sites used to steal company credentials

ID: 956346c0-9225-5da6-81a0-509bdb79012a

STIX ID: report--956346c0-9225-5da6-81a0-509bdb79012a

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-03-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Microsoft observed the Storm-2561 campaign distributing fake enterprise VPN clients (spoofing vendors like Ivanti, Cisco, Fortinet, Sophos, SonicWall, etc.) via SEO-poisoned sites that link to a malicious ZIP containing a trojanized MSI. When executed the installer deploys a fake Pulse client (Pulse.exe), a loader (dwmapi.dll) and a Hyrax infostealer (inspector.dll), captures VPN credentials and connectionsstore.dat, achieves persistence via RunOnce, and then attempts to hide the compromise by showing an installation error and redirecting victims to the legitimate vendor site; Microsoft published IoCs and mitigation guidance including Defender/EDR protections and MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.