Csoonline Storm-2561 Targets VPN Users with SEO Poisoning and Fake Clients
Article Content
- •Storm-2561 uses SEO poisoning to distribute fake VPN clients that steal credentials.
- •The malware is signed with a legitimate certificate, allowing it to evade detection.
- •Microsoft has issued warnings and mitigation strategies for affected organizations.
Cybercriminal group Storm-2561 is exploiting SEO poisoning to distribute trojanized VPN clients, primarily targeting enterprise users of popular VPN solutions like Pulse Secure, Ivanti, and Cisco. The attackers manipulate search engine results to redirect users to spoofed sites that closely mimic legitimate VPN vendors, leading to the download of a malicious ZIP file containing a fake MSI installer. This installer drops a fake application and a variant of the Hyrax infostealer, which captures and exfiltrates VPN credentials and configuration data. The malware is signed with a valid certificate from Taiyuan Lihua Near Information Technology Co., Ltd., allowing it to bypass security warnings. Microsoft first detected this activity in January 2026, although the group has been active since May 2025. The campaign highlights the increasing sophistication of infostealers, which are now often paired with remote access trojans. Microsoft has provided mitigation guidance and indicators of compromise to help organizations defend against this threat.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track Storm-2561, GPUGate and Pulse Secure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…