logo

Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal Credentials

ID: b2711365-d3c2-5d4e-becd-9ec43303b416

STIX ID: report--b2711365-d3c2-5d4e-becd-9ec43303b416

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Microsoft disclosed a credential-theft campaign by the Storm-2561 cluster that uses SEO poisoning to redirect users searching for legitimate enterprise VPN clients to attacker-controlled sites and GitHub-hosted ZIPs containing digitally signed MSI installers. The trojanized installers sideload malicious DLLs, present fake VPN sign-in dialogs to capture credentials, use RunOnce for persistence, and deploy a Hyrax variant to exfiltrate VPN credentials; Microsoft removed the repositories and revoked the signing certificate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.