fortinet

1 article
sort: new top best
clear filter
0 5/10

Threat actor Storm-2561 distributes fake VPN clients from major vendors (Ivanti, Cisco, Fortinet, Sophos, Sonicwall, Check Point, WatchGuard) via SEO poisoning to steal enterprise VPN credentials and configuration data. The malware bundle includes the Hyrax infostealer, creates persistence via RunOnce registry keys, and displays fake login interfaces before redirecting users to legitimate vendor sites to avoid detection.

Storm-2561 Hyrax Pulse.exe dwmapi.dll inspector.dll connectionsstore.dat Taiyuan Lihua Near Information Technology Co., Ltd. Microsoft GitHub Windows Defender SmartScreen
bleepingcomputer.com · Bill Toulas · 10 hours ago · details