logo

VPN Credential Theft

Storm-2561 runs an SEO‑poisoning campaign that lures users to spoofed vendor sites and attacker‑hosted repos serving digitally signed, trojanized VPN installers that sideload malicious DLLs (Hyrax), harvest and exfiltrate VPN credentials and config data, maintain persistence (e.g., RunOnce), and hide the compromise with decoy errors while researchers publish IOCs and mitigations.

List of posts related to this topic

Post TitleDate PublishedDescribes IncidentFeed
Attackers Use SEO Poisoning and Signed Trojans to Steal VPN Credentials2026-03-17TruecybersecurityNews.com
Not Subscribed
The Fake VPN Trap: Microsoft Warns of Storm-2561 SEO Poisoning Campaigns Stealing Corporate Credentials2026-03-17Truesecurityonline.info
Not Subscribed
Storm-2561 lures victims to spoofed VPN sites to harvest corporate logins2026-03-14TrueSecurity Affairs
Not Subscribed
Credential-stealing crew spoofs VPN clients from Cisco, Fortinet, and others2026-03-13TrueThe Register (Security)
Not Subscribed
Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal Credentials2026-03-13TrueThe Hacker News
Not Subscribed
Fake enterprise VPN sites used to steal company credentials2026-03-13TrueBleeping Computer
Not Subscribed
Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft2026-03-12TrueMicrosoft Security
Not Subscribed
Ongoing Widespread Credential Harvesting Campaign Targets VPN Providers2026-01-13TrueWatchGuard Secplicity Blog
Not Subscribed

1–8 of 8