Back to Feed
MalwareMar 13, 2026

Fake enterprise VPN sites used to steal company credentials

Threat actor Storm-2561 is distributing fake enterprise VPN clients impersonating Ivanti, Cisco, and Fortinet to harvest VPN credentials from users. This credential theft campaign leverages fake VPN applications to deceive employees into compromising their authentication credentials, enabling unauthorized access to corporate networks.

Summary

Threat actor Storm-2561 is distributing fake enterprise VPN clients impersonating Ivanti, Cisco, and Fortinet to harvest VPN credentials from users. This credential theft campaign leverages fake VPN applications to deceive employees into compromising their authentication credentials, enabling unauthorized access to corporate networks.

Indicators of Compromise

  • malware — Storm-2561