Back to News
Cyber Attack

Storm-2561 Uses SEO Poisoning to Steal VPN Credentials

Storm-2561 Uses SEO Poisoning to Steal VPN Credentials

Microsoft disclosed a credential-theft campaign it attributed to the threat cluster Storm-2561 that uses search engine optimization poisoning to push fake VPN clients to victims.

Microsoft said the campaign redirects users searching for legitimate enterprise VPN software to attacker-controlled sites that serve malicious ZIP files. “The campaign redirects users searching for legitimate enterprise software to malicious ZIP files on attacker-controlled websites to deploy digitally signed trojans that masquerade as trusted VPN clients while harvesting VPN credentials,” Microsoft said.

Researchers at Cyjax first documented the actor’s SEO poisoning approach, showing how searches for vendors such as SonicWall, Hanwha Vision, and Pulse Secure (now Ivanti Secure Access) on Bing were redirected to bogus sites that delivered MSI installers embedding the Bumblebee loader, Cyjax found. Zscaler later reported a follow-up campaign that trojanized an Ivanti Pulse Secure client via a fake site named “ivanti-vpn[.]org”.

Microsoft said it observed a similar campaign in mid-January 2026 and linked the activity to Storm-2561, noting the threat actor is known for impersonating popular vendors and abusing search rankings. The installers discussed by Microsoft and the other firms sideload malicious DLLs during installation and deploy an information stealer to capture credentials.

According to Microsoft, the malware uses a Hyrax variant to collect and exfiltrate VPN credentials and displays a convincing fake VPN sign-in dialog to capture usernames and passwords. Victims then see an error message and are sometimes redirected to the real vendor site so the attack appears less suspicious, Microsoft said. The malware also persists by setting a Windows RunOnce registry key so it runs after reboot, Microsoft added.

Microsoft highlighted another worry: the attackers abused trusted platforms to host payloads. Microsoft said attacker-controlled GitHub repositories were used to store ZIP files containing the trojanized MSI installers. “This campaign exhibits characteristics consistent with financially motivated cybercrime operations employed by Storm-2561,” Microsoft said, and noted the malicious components were digitally signed by “Taiyuan Lihua Near Information Technology Co., Ltd.”

Microsoft said it removed the attacker-controlled GitHub repositories and revoked the certificate to disrupt the operation. Cyjax and Zscaler’s earlier reporting helped map the campaign’s evolution, the companies said.

To reduce risk, Microsoft advised organizations and users to enable multi-factor authentication on all accounts, verify downloads and vendor sites before installing software, and exercise caution when following search results. “Be wary of unexpected prompts for credentials and validate installers with vendor channels,” Microsoft recommended.

For practical, actionable steps to reduce your exposure to these kinds of attacks, see our guide on protecting yourself from cyber attacks in 10 easy steps. If an incident does occur, follow the recommended procedures in our step-by-step incident response guide to contain and remediate the impact.

#Storm2561 #VPNSecurity #SEOpoisoning #CredentialTheft #CyberSecurity