Microsoft is warning businesses that the Storm-2561 is interfering with search engine results to offer modified VPN clients and steal corporate credentials, covering their tracks before victims suspect the theft. According to Microsoft Threat Intelligence, the group is promoting fake websites at the top of results for queries like “Pulse VPN download” or “Pulse Secure client,” redirecting users to digitally signed malware hosted on GitHub.

“The techniques used in this campaign highlight how malicious actors continue to exploit trusted platforms and software to evade user suspicion and steal sensitive information,” the advisory said. Microsoft Defender Experts first detected the activity in mid-January 2026, although the malicious actor has been active since May 2025 and is known for distributing malware through SEO poisoning and copying popular enterprise software vendors.
See also: Hive0163 uses AI malware Slopoly in ransomware attacks
Storm-2561: Combination of infostealers and RATs
The campaign comes as infostealers become more dangerous. Security researchers have observed that infostealers are increasingly being bundled with remote access, giving attackers both stolen credentials and persistent network access (from a single infection). Storm-2561 follows this pattern exactly. Within the attack chain, Microsoft observed fake pages that mimicked Fortinet, Ivanti, Cisco, SonicWall, Sophos, Checkpoint, and WatchGuard, along with two domains— vpn-fortinet[.]com and ivanti-vpn[.]org — hosting malicious ZIP files on GitHub.
The malware arrives as a ZIP file containing a Windows installation package. When a user launches the downloaded installer, it installs a application Pulse Secure in a directory that closely mimics a legitimate Pulse Secure installation path.
“This installation path is integrated with legitimate VPN software to appear trustworthy and avoid user suspicion,” the advisory noted.
The installer loads two malicious DLL files alongside the fake application. One acts as a memory loader. The other, inspector.dll, is a variant of the Hyrax infostealer. It extracts stored VPN credentials and URI data and exports them to an infrastructure controlled by the attackers.
“The malicious ZIP files, containing fake installation files, were hosted on GitHub repositories that have now been removed,” the advisory noted.
See also: Polyfill supply chain attack 2024: North Korean hackers involved
The delivery method resembles tactics seen in recent campaigns. In August 2025, Arctic Wolf researchers uncovered the GPUGate malware , distributed via GitHub repositories and Google ads , using MSI-packaged payloads and credential extraction in a nearly identical delivery chain.

Signed certificates to avoid detection
The MSI file and malicious DLLs are signed with a valid digital certificate from “Taiyuan Lihua Near Information Technology Co., Ltd.”, Microsoft said. This allowed the malware to bypass Windows security warnings about unsigned code, potentially bypass application whitelisting policies, and reduce alerts from tools that focus on unsigned executables.
This certificate has since been revoked. Microsoft identified several additional files signed with the same certificate, all impersonating VPN software from different vendors.
Attackers cover their tracks after stealing credentials
After being caught, the fake client displays an error message indicating that the installation failed. It then directs the user to download the legitimate VPN client from the vendor’s official website. “In some cases, it opens the user’s browser to the legitimate VPN website,” Microsoft said. If the real VPN installs and works as expected, the victim has no indication of a breach. Storm-2561 also establishes a persistent presence via the Windows RunOnce registry key, ensuring that the malware runs on every reboot.
See also: Iranian hackers claim responsibility for wiper attack on Stryker
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The post-credential theft redirection strategy eliminates behavioral anomalies that might otherwise trigger a security audit. SEO poisoning campaigns have long relied on deception to avoid leaving a trail. Storm-2561 takes this a step further by redirecting victims to legitimate software after the theft. Thus, it leaves no obvious trace of the breach.

Protection
Microsoft recommended that organizations enforce multi-factor authentication on all accounts without exception. Corporate credentials should not be stored in browser-based password vaults that are secured with personal credentials. Organizations should also disable browser password synchronization on managed devices via Group Policy
On the endpoint side, Microsoft advised running endpoint detection and response in block mode and enabling network and web protection in Microsoft Defender for Endpoint. “Encourage users to use Microsoft Edge and other browsers that support SmartScreen, which detects and blocks malicious websites, including phishing sites, scam sites, and sites that contain exploits and host malware,” the advisory said.
