Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
search-ad-manipulationcredential-stealer-activityidentity-impersonation-fraudremote-access-implant

SEO Poisoning and Fake Software Downloads Used to Deliver Credential Theft and RAT Malware

Updated 2mo agoFirst seen Mar 17, 20268 sources

Threat actors are using software impersonation and SEO poisoning to push victims toward fake download sites for trusted enterprise and IT tools, then delivering malware through trojanized installers. In one campaign, Storm-2561 used spoofed VPN vendor pages for products such as Pulse Secure, Fortinet, and Ivanti to steal enterprise VPN credentials. The malicious packages were hosted on GitHub, signed with a certificate issued to "Taiyuan Lihua Near Information Technology Co., Ltd.", and designed to show an error before redirecting victims to the legitimate vendor site, reducing suspicion while exfiltrating credentials.

A separate but closely related campaign used fake FileZilla download pages to distribute a Remote Access Trojan through multi-stage loaders and DLL sideloading. Attackers bundled legitimate FileZilla software with a malicious version.dll, or dropped the DLL during installation so the malware would execute while the expected application appeared to install normally. Both reports describe the same broader intrusion pattern: adversaries abusing trusted brands, realistic lookalike websites, and legitimate software packaging to compromise users who believe they are downloading authentic tools. A separate Warlock intrusion analysis describing web shells, lateral movement, tunneling, and ransomware activity is a different incident and does not match this malware-delivery story.

Share:
SEO Poisoning and Fake Software Downloads Used to Deliver Credential Theft and RAT Malware
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
Apr 26, 20262mo ago

Fake Foxit PDF Reader installer campaign deploys UltraVNC malware

Attackers impersonated Foxit PDF Reader with trojanized installer packages that masqueraded as legitimate software downloads. The fake installer deployed UltraVNC to establish stealthy remote access on compromised systems, reflecting a software-impersonation and social-engineering malware campaign.

Foxit Impersonation: Fake PDF Installer Deploys VNC Malware - Infosec.Pub
Apr 16, 20262mo ago

Gurucul reports fake TestDisk site installing trojanized ScreenConnect

Gurucul disclosed an SEO-poisoning campaign redirecting users searching for TestDisk to the spoofed domain testdisk[.]dev, where a fake PhotoRec installer delivered a ZIP containing a renamed Microsoft Setup binary that side-loaded a malicious autorun.dll. The multi-stage infection ultimately installed legitimate TestDisk software alongside a trojanized ScreenConnect client for persistent remote access, and the report published related IOCs including domain, URL, IP 193.42.11.108, and a SHA-256 hash.

SEO Poisoning Leads to Sideloaded Microsoft Binary and #RMM Installation | Community Portal | Gurucul
Mar 27, 20263mo ago

Forensic analysis links fake Sysinternals tool to infostealer infection

A forensic investigation found that a user downloaded and ran a fake Sysinternals executable from a malicious website, leading to a trojan and information stealer infection. Analysis showed the malware stole user input and browser session cookies, contacted command-and-control infrastructure, and dropped a second-stage payload named vmtoolsIO.exe that established persistence via the VMwareIOHelperService auto-start service.

Digital Forensics: Analyzing Fake Software - Hackers Arise
Mar 23, 20263mo ago

NCC Group and FOX-IT uncover SEO-poisoning campaign delivering AsyncRAT

Investigators uncovered a long-running campaign active since October 2025 that used fake download pages for more than 25 popular applications to deliver ZIP archives containing legitimate software and malicious DLL sideloading components. The infection chain silently installed ScreenConnect and ultimately deployed an AsyncRAT variant with credential theft, keylogging, clipboard monitoring, and cryptocurrency clipper capabilities.

SEO Poisoning Campaign Impersonates 25+ Popular Apps to Deliver AsyncRAT Since October 2025
Mar 17, 20263mo ago

Microsoft discloses Storm-2561 VPN credential theft campaign

Microsoft publicly identified Storm-2561 as behind an ongoing credential theft operation that used SEO poisoning and spoofed VPN software sites to target enterprise users. The disclosure highlighted the risk of stolen VPN access enabling lateral movement, data theft, and follow-on attacks across industries and regions.

Mar 16, 20263mo ago

Technical details published on FileZilla RAT capabilities and C2 evasion

Analysis revealed the RAT supports credential theft, keylogging, screenshot capture, and hidden remote control through HVNC. The malware also used anti-VM and anti-sandbox checks and communicated with the command-and-control domain welcome.supp0v3.com via DNS-over-HTTPS through Cloudflare's 1.1.1.1 resolver.

EST Security identifies fake FileZilla sites delivering a RAT

EST Security analysts identified an active campaign using fake websites impersonating the official FileZilla download page to infect Windows users. The attackers bundled legitimate FileZilla software with a malicious DLL and used DLL sideloading plus a multi-stage in-memory loader to deploy a remote access trojan.

Mar 1, 20264mo ago

eSentire reports Kong RAT SEO-poisoning campaign targeting Chinese-speaking developers

eSentire disclosed a multi-stage malware campaign observed in March 2026 that used SEO poisoning and fake Chinese-language software sites for tools including FinalShell, Xshell, QuickQ, and Clash to deliver Kong RAT. The campaign targeted Chinese-speaking developers and IT professionals and used Alibaba Cloud OSS infrastructure, DLL sideloading, shellcode execution, and a COM UAC bypass for post-compromise control.

Multi-Stage SEO Poisoning Campaign Targets Chinese-Speaking Developers with Kong RAT | eSentire
Oct 31, 20258mo ago

Blackpoint reports fake Teams installers dropping Oyster malware

Blackpoint SOC reported a campaign using SEO poisoning and malvertising to lure users searching for Microsoft Teams to spoofed download sites serving trojanized installers such as MSTeamsSetup.exe. The installer deployed the Oyster (Broomstick) backdoor, established persistence with a scheduled task named CaptureService, and used signed binaries and spoofed domains to appear legitimate.

Malicious Teams Installers Drop Oyster Malware - Blackpoint
May 1, 20251y ago

Storm-2561 uses signed trojanized VPN installers to steal credentials

In the campaign, attackers distributed fake MSI installers that dropped legitimate-looking executables and malicious DLLs, including a Hyrax infostealer variant, to steal VPN credentials and configuration data. Microsoft found the malware was signed with a certificate issued to Taiyuan Lihua Near Information Technology Co., Ltd., which was later revoked.

Storm-2561 begins SEO-poisoning campaign targeting VPN users

Microsoft said the financially motivated Storm-2561 campaign has been active since at least May 2025, using SEO manipulation to lure enterprise users to spoofed VPN software sites. The actor impersonated brands including Pulse Secure, Fortinet, Ivanti, GlobalProtect, and Sophos Connect to distribute malicious ZIP packages.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

38 LINKEDOpen in app
Affected products
12 linked
UltravncWindowsVlc Media PlayerWechatTelegramWhatsappAnydeskScreenconnectSysinternalsXshellFilezillaPutty
Organizations
21 linked
Foxit SoftwareMicrosoft CorporationCloudflareVideolanAlibaba CloudFilezillaTencentBlackpoint CyberPalo Alto NetworkseSentireNCC GroupFox-ItConnectwiseBroadcomESTsecurity4th State OyManagement Performance Auto Service Ltd.GuruculNRM NETWORK RISK MANAGEMENT INCAntbox Networks LimitedLe Holdings Co., Ltd.
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.