Storm-2561 lures victims to spoofed VPN sites to harvest corporate logins
2026-03-14T14:51:48Z•f167b174b9174ffb5104e0949055b7d3867bd37d8858b87b46c7b11c3593f44d
AI-assisted malwareAVreconAlly pluginAppleCISA KEVCiscoCorunaFortinetGoogle ChromeHive0163InterpolIvantiOperation Synergia IIISEO poisoningSQL injectionSlopolySocksEscortStorm-2561VPN spoofingWordPressbotnetcredential theftiOS patchnuclear research attack detectionransomware
What happened
Multiple high-impact incidents and disclosures: Microsoft-linked researchers attribute a credential-theft campaign to Storm-2561 that uses SEO-poisoned search results to host spoofed Ivanti, Cisco and Fortinet VPN sites and harvest corporate credentials. International law enforcement (Operation Synergia III) dismantled ~45,000 malicious IPs/servers and made 94 arrests; US/EU authorities also disrupted the SocksEscort proxy service backed by the AVrecon botnet (≈360,000 infected devices). IBM/other researchers report Hive0163 using AI-assisted Slopoly malware to maintain persistence in ransom-•
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- f167b174b9174ffb5104e0949055b7d3867bd37d8858b87b46c7b11c3593f44d
- Enrichment time
- 2026-03-14T14:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.