Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
search-ad-manipulationcredential-stealer-activityidentity-impersonation-fraudloader-delivery-mechanism

Storm-2561 SEO Poisoning Campaign Distributing Fake VPN Clients

Updated 3mo agoFirst seen Mar 13, 20262 sources

Microsoft disclosed that threat actor Storm-2561 used SEO poisoning to lure users searching for legitimate enterprise VPN software to attacker-controlled sites hosting malicious ZIP archives. The campaign delivered digitally signed trojans masquerading as trusted VPN clients, with payloads designed to steal VPN credentials; Microsoft said the GitHub repositories used to host the ZIP files were removed and the abused signing certificate was revoked. The activity was identified in mid-January 2026, and Microsoft linked it to a broader Storm-2561 pattern of impersonating well-known software vendors and abusing trusted platforms to improve legitimacy and evade suspicion.

The reporting is not fluff because it contains a specific threat campaign, attribution, delivery chain, and defensive implications. A broader weekly bulletin also referenced the same fake VPN client / credential theft activity as one item among several security developments, making it relevant but less detailed. A separate newsletter on detection engineering maturity and product promotion is unrelated to the Storm-2561 intrusion set and should be excluded from the incident summary.

Share:
Storm-2561 SEO Poisoning Campaign Distributing Fake VPN Clients
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 12, 20263mo ago

Microsoft publishes Storm-2561 attribution and IOCs

Microsoft publicly attributed the fake VPN campaign to Storm-2561 and released technical details, mitigations, detections, hunting guidance, and indicators of compromise including hashes, domains, and C2 information.

Malicious signing certificate is revoked and GitHub payloads removed

The campaign's binaries were signed with a legitimate certificate tied to 'Taiyuan Lihua Near Information Technology Co., Ltd.'; Microsoft said the certificate has since been revoked and the GitHub repositories hosting the payloads were taken down.

Jan 15, 20265mo ago

Trojanized VPN installers steal credentials and VPN configs

The fake VPN packages dropped a Pulse Secure-like application and side-loaded malicious DLLs, including a Hyrax variant that captured and exfiltrated VPN credentials and configuration data before redirecting users to the legitimate VPN client.

Microsoft identifies Storm-2561 fake VPN credential-theft campaign

In mid-January 2026, Microsoft Defender Experts identified a campaign in which victims were lured via SEO poisoning to spoofed enterprise VPN download sites and attacker-controlled GitHub releases hosting trojanized installers.

May 1, 20251y ago

Storm-2561 begins activity impersonating software vendors

Microsoft said the financially motivated threat actor Storm-2561 has been active since May 2025, using search-result impersonation of popular software vendors as part of its operations.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

74 LINKEDOpen in app
Affected products
8 linked
WhatsappWindows 11Windows Server 2025TiktokWindows HelloMessengerGithubMicrosoft Defender For Endpoint
Organizations
43 linked
Microsoft CorporationGitHubCheck Point Software TechnologiesK7 ComputingFlashpointDomainToolsNightwingCloudflareAnthropicDocuSignAdvanced Micro DevicesCofenseTikTokMeta PlatformsOpenaiProofpointConnectwiseCYFIRMAQuarkslabAdobeWizRouterHosting LLCBitsightFlareMcKinsey & CompanyAryakaMeshcentralGoogleTactical RMMTrustConnect Software PTY LTDBombadil SystemsCodeWallPulse SecureCisco SystemsZscalerPalo Alto NetworksWatchGuard TechnologiesFortinetIvantiCYJAXSonicwallSophosTaiyuan Lihua Near Information Technology Co., Ltd.
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.