Storm-2561 Uses Fake Fortinet, Ivanti VPN Sites to Drop Hyrax Infostealer

2026-03-17T20:51:51Z2ab6d3c9706bc411344e741db683d8d9d363f91c6be9dacda6fde4c5dfb37ae2
AWS BedrockAgentCoreClickFixCompanies HouseDNS exfiltrationGitHubHyraxLiveChat phishingMFA compromiseMacSyncRedditSteamStorm-2561Vidar 2.0WebFilingcode interpretercrypto theftdata leakfake AI toolsfake VPN sitesfake game cheatsinfostealerphishingsecrets leaksupply chain

What happened

Multiple contemporaneous threats and data-exposure incidents were reported: Storm-2561 is using convincing fake Fortinet and Ivanti VPN pages to drop the Hyrax infostealer; a ClickFix/Claude-themed campaign distributes MacSync malware via fake AI extensions and ads targeting developers; Vidar 2.0 is being propagated as fake game cheats on GitHub and Reddit to steal crypto, tokens and files. Researchers disclosed an AWS Bedrock AgentCore Code Interpreter sandbox issue that can leak sensitive cloud data via DNS, while GitGuardian reported an 81% surge in AI-service secret leaks (≈29M secrets on

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
2ab6d3c9706bc411344e741db683d8d9d363f91c6be9dacda6fde4c5dfb37ae2
Enrichment time
2026-03-17T20:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Storm-2561 Uses Fake Fortinet, Ivanti VPN Sites to Drop Hyrax Infostealer · Baitaphish