Storm-2561 lures victims to spoofed VPN sites to harvest corporate logins

2026-03-14T14:51:48Zf167b174b9174ffb5104e0949055b7d3867bd37d8858b87b46c7b11c3593f44d
AI-assisted malwareAVreconAlly pluginAppleCISA KEVCiscoCorunaFortinetGoogle ChromeHive0163InterpolIvantiOperation Synergia IIISEO poisoningSQL injectionSlopolySocksEscortStorm-2561VPN spoofingWordPressbotnetcredential theftiOS patchnuclear research attack detectionransomware

What happened

Multiple high-impact incidents and disclosures: Microsoft-linked researchers attribute a credential-theft campaign to Storm-2561 that uses SEO-poisoned search results to host spoofed Ivanti, Cisco and Fortinet VPN sites and harvest corporate credentials. International law enforcement (Operation Synergia III) dismantled ~45,000 malicious IPs/servers and made 94 arrests; US/EU authorities also disrupted the SocksEscort proxy service backed by the AVrecon botnet (≈360,000 infected devices). IBM/other researchers report Hive0163 using AI-assisted Slopoly malware to maintain persistence in ransom-•

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
f167b174b9174ffb5104e0949055b7d3867bd37d8858b87b46c7b11c3593f44d
Enrichment time
2026-03-14T14:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Storm-2561 lures victims to spoofed VPN sites to harvest corporate logins · Baitaphish