Storm-2561 Uses Fake Fortinet, Ivanti VPN Sites to Drop Hyrax Infostealer
2026-03-17T20:51:51Z•2ab6d3c9706bc411344e741db683d8d9d363f91c6be9dacda6fde4c5dfb37ae2
AWS BedrockAgentCoreClickFixCompanies HouseDNS exfiltrationGitHubHyraxLiveChat phishingMFA compromiseMacSyncRedditSteamStorm-2561Vidar 2.0WebFilingcode interpretercrypto theftdata leakfake AI toolsfake VPN sitesfake game cheatsinfostealerphishingsecrets leaksupply chain
What happened
Multiple contemporaneous threats and data-exposure incidents were reported: Storm-2561 is using convincing fake Fortinet and Ivanti VPN pages to drop the Hyrax infostealer; a ClickFix/Claude-themed campaign distributes MacSync malware via fake AI extensions and ads targeting developers; Vidar 2.0 is being propagated as fake game cheats on GitHub and Reddit to steal crypto, tokens and files. Researchers disclosed an AWS Bedrock AgentCore Code Interpreter sandbox issue that can leak sensitive cloud data via DNS, while GitGuardian reported an 81% surge in AI-service secret leaks (≈29M secrets on
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 2ab6d3c9706bc411344e741db683d8d9d363f91c6be9dacda6fde4c5dfb37ae2
- Enrichment time
- 2026-03-17T20:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.