Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal Credentials
ID: b2711365-d3c2-5d4e-becd-9ec43303b416
STIX ID: report--b2711365-d3c2-5d4e-becd-9ec43303b416
Feed Name: The Hacker News
Microsoft disclosed a credential-theft campaign by the Storm-2561 cluster that uses SEO poisoning to redirect users searching for legitimate enterprise VPN clients to attacker-controlled sites and GitHub-hosted ZIPs containing digitally signed MSI installers. The trojanized installers sideload malicious DLLs, present fake VPN sign-in dialogs to capture credentials, use RunOnce for persistence, and deploy a Hyrax variant to exfiltrate VPN credentials; Microsoft removed the repositories and revoked the signing certificate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
