Storm-2561 Uses SEO Poisoning, Fake Signed VPN Apps to Steal Enterprise Credentials
Storm-2561, a financially motivated threat actor, is conducting a credential theft campaign utilizing SEO poisoning and counterfeit VPN installers to illicitly obtain enterprise VPN credentials.
Storm-2561, a financially motivated threat actor, is conducting a credential theft campaign utilizing SEO poisoning and counterfeit VPN installers to illicitly obtain enterprise VPN credentials.
Active since May 2025, Storm-2561 leverages user trust in search results and legitimate VPN brands to deploy malware under the guise of authentic remote access tools.
The attackers employ SEO poisoning to elevate malicious sites in search results, redirecting victims to fraudulent VPN download sites on domains they control, such as vpn-fortinet[.]com and ivanti-vpn[.]org.
From these counterfeit vendor pages, users were directed to a now-defunct malicious GitHub repository hosting a ZIP archive named VPN-CLIENT.zip, which contained a trojanized MSI installer.
In January 2026, Microsoft Defender Experts identified a new Storm-2561 campaign targeting users searching for enterprise VPN software, including Pulse Secure and other popular VPN brands.
The installer masquerades as a legitimate VPN client but deploys signed malware components intended to harvest VPN credentials and configuration data.
Upon execution, the malicious MSI installs Pulse.exe and additional DLLs, including dwmapi.dll and inspector.dll, under a path resembling a real Pulse Secure installation, such as %CommonFiles%\Pulse Secure.
The dwmapi.dll component functions as an in-memory loader that executes embedded shellcode to load inspector.dll, identified as a Hyrax information-stealing malware variant.
The installer masquerades as a legitimate VPN client but deploys signed malware components intended to harvest VPN credentials and configuration data.
Hyrax targets URI and VPN sign-in details, including configuration data from C:\ProgramData\Pulse Secure\ConnectionStore\connectionstore.dat, exfiltrating them to a command-and-control server at 194.76.226[.]93:8080.
The operation involves abuse of a legitimate code-signing certificate issued to Taiyuan Lihua Near Information Technology Co., Ltd., which has been revoked.
The MSI and malicious DLLs are signed, allowing them to bypass default Windows warnings about unsigned code and potentially evade application allowlisting and security tools that flag unsigned executables.
Additional fake VPN binaries, including those named Pulse.exe, Sophos-Connect-Client.exe, GlobalProtect-VPN.exe, VPN-Client.exe, and vpn.exe, were also signed with the same certificate, indicating a broader malware distribution effort.
The fake VPN client mimics the legitimate Pulse Secure client and prompts users for VPN credentials. Instead of establishing a VPN tunnel, it captures the entered credentials and exfiltrates them to the Storm-2561 C2 server, then displays a fake error message claiming the installation failed.
To avoid suspicion, the malware instructs users to download the genuine VPN client, sometimes opening the official vendor site, leading victims to install a working, legitimate VPN without obvious signs of compromise.
Defender for Endpoint identifies anomalies such as unexpected DLL side-loading by VPN installers and suspicious registry changes used for persistence.
The persistence mechanism involves configuring Pulse.exe to run at reboot via the Windows RunOnce registry key.
Microsoft Defender Antivirus detects campaign payloads as Trojan:Win32/Malgent and TrojanSpy:Win64/Hyrax. Microsoft Defender for Endpoint in block mode can halt active Malgent and Hyrax activity and alert on VPN processes initiating from unusual locations.
To minimize exposure to similar campaigns, Microsoft recommends enabling cloud-delivered protection and EDR in block mode, activating network and web protection, enforcing multifactor authentication, and disabling credential storage in personal browsers or password vaults.
Organizations should apply attack surface reduction rules to restrict low-prevalence binaries and utilize advanced hunting queries to identify files signed by Taiyuan Lihua Near Information Technology Co., Ltd. or detect malicious DLL activity under Pulse Secure paths.
Based on reporting by GBHackers.
