Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
Storm-2561 is a threat actor group active since 2025 that uses SEO poisoning techniques to distribute fake VPN clients containing signed trojans designed to steal VPN credentials. The campaign impersonates trusted brands and abuses legitimate services to increase credibility and evade detection. Microsoft Security Blog provides TTPs, IOCs, and mitigation guidance for this ongoing threat.
Summary
Storm-2561 is a threat actor group active since 2025 that uses SEO poisoning techniques to distribute fake VPN clients containing signed trojans designed to steal VPN credentials. The campaign impersonates trusted brands and abuses legitimate services to increase credibility and evade detection. Microsoft Security Blog provides TTPs, IOCs, and mitigation guidance for this ongoing threat.
Indicators of Compromise
- malware — Storm-2561