Skip to main content
Mallory
7 malware families

Storm 2561

Also known asStorm 2561

Storm-2561 is a Microsoft-tracked cybercriminal threat actor active since May 2025. Microsoft describes it as a financially motivated threat activity cluster known for distributing malware through SEO poisoning and impersonating popular software vendors. The actor has run SEO-poisoning campaigns that redirect users searching for legitimate enterprise software, particularly VPN products, to spoofed download sites and attacker-controlled GitHub repositories hosting malicious ZIP files and trojanized installers. Microsoft reported that Storm-2561 used fake VPN clients to install signed trojans and steal VPN credentials, including campaigns involving trojanized Ivanti Pulse Secure and SonicWall NetExtender-themed software. Reported malware and tooling associated with these campaigns include a Hyrax infostealer variant used to harvest VPN credentials, and earlier activity documented by Microsoft and others involved delivery of the Bumblebee loader. Microsoft also stated that Storm-2561 abuses legitimate services as part of its operations and mimics trusted brands to increase victim trust. Microsoft further linked Storm-2561 to Fox Tempest’s malware-signing-as-a-service platform. According to the cited reporting, Storm-2561 was one of the threat actors that used Fox Tempest-signed malware in active intrusions. Those downstream delivery methods included legitimate purchased advertisements, malvertising, SEO poisoning, and fake ads. Storm-2561 is also listed among Fox Tempest customers alongside Vanilla Tempest, Storm-0501, and Storm-0249. No additional aliases or sub-groups for Storm-2561 are directly provided in the content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics33 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
2 techniques
T1593
Search Open Websites/Domains
T1598×2
Phishing for Information
TA0042
Resource Development
3 techniques
T1583×2
Acquire Infrastructure
T1588
Obtain Capabilities
T1588.003
Code Signing Certificates
T1608
Stage Capabilities
T1608.006×5
SEO Poisoning
TA0001
Initial Access
1 technique
T1566
Phishing
T1566.002
Spearphishing Link
TA0002
Execution
2 techniques
T1204
User Execution
T1204.002×2
Malicious File
T1574
Hijack Execution Flow
T1574.001
DLL
TA0003
Persistence
1 technique
T1547
Boot or Logon Autostart Execution
T1547.001×3
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
1 technique
T1547
Boot or Logon Autostart Execution
T1547.001×3
Registry Run Keys / Startup Folder
TA0005
Stealth
3 techniques
T1036×4
Masquerading
T1574
Hijack Execution Flow
T1574.001
DLL
T1620×2
Reflective Code Loading
TA0112
Defense Impairment
1 technique
T1553
Subvert Trust Controls
T1553.002×6
Code Signing
TA0006
Credential Access
3 techniques
T1056
Input Capture
T1056.001
Keylogging
T1555×4
Credentials from Password Stores
T1649×2
Steal or Forge Authentication Certificates
TA0009
Collection
1 technique
T1056
Input Capture
T1056.001
Keylogging
TA0011
Command and Control
1 technique
T1105×2
Ingress Tool Transfer
TA0010
Exfiltration
2 techniques
T1041
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
IOCS

Observables

31 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping18

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal7

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables31

Domains, IPs, and hashes tied to this actor, refreshed continuously.