Storm 2561
Storm-2561 is a Microsoft-tracked cybercriminal threat actor active since May 2025. Microsoft describes it as a financially motivated threat activity cluster known for distributing malware through SEO poisoning and impersonating popular software vendors. The actor has run SEO-poisoning campaigns that redirect users searching for legitimate enterprise software, particularly VPN products, to spoofed download sites and attacker-controlled GitHub repositories hosting malicious ZIP files and trojanized installers. Microsoft reported that Storm-2561 used fake VPN clients to install signed trojans and steal VPN credentials, including campaigns involving trojanized Ivanti Pulse Secure and SonicWall NetExtender-themed software. Reported malware and tooling associated with these campaigns include a Hyrax infostealer variant used to harvest VPN credentials, and earlier activity documented by Microsoft and others involved delivery of the Bumblebee loader. Microsoft also stated that Storm-2561 abuses legitimate services as part of its operations and mimics trusted brands to increase victim trust. Microsoft further linked Storm-2561 to Fox Tempest’s malware-signing-as-a-service platform. According to the cited reporting, Storm-2561 was one of the threat actors that used Fox Tempest-signed malware in active intrusions. Those downstream delivery methods included legitimate purchased advertisements, malvertising, SEO poisoning, and fake ads. Storm-2561 is also listed among Fox Tempest customers alongside Vanilla Tempest, Storm-0501, and Storm-0249. No additional aliases or sub-groups for Storm-2561 are directly provided in the content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
Observables
31 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named by Microsoft as a threat group that utilized malware signed through Fox Tempest's fraudulent signing service.
Named as a customer of Fox Tempest's malware-signing service.
Named as a threat actor linked to the Fox Tempest malware-signing service.
Named activity cluster observed using Fox Tempest-signed malware in real-world intrusions.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.