Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft

2026-03-13T20:52:18Z63f3fafecdac96a9ea7634daa0ac28e4ae6a6895adfe40e845cf118c804af7a6
IOCsSEO poisoningStorm-2561code signing abusecredential theftfake VPNmalware distributionmitigation guidancesigned malwaresupply-chain mimicrytrojan

What happened

Microsoft reports that the Storm-2561 campaign (active since 2025) uses SEO poisoning to surface fake VPN downloads that mimic trusted vendors and abuse legitimate services. The malicious installers deploy signed trojans which harvest VPN credentials and enable further access. The blog provides TTPs, IOCs, and mitigation guidance (verify vendor download sources, harden certificate/code-signing controls, monitor for suspicious RMM and VPN-related activity, enforce MFA and credential protections).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
63f3fafecdac96a9ea7634daa0ac28e4ae6a6895adfe40e845cf118c804af7a6
Enrichment time
2026-03-13T20:52:18Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.