seo-poisoning

2 articles
sort: new top best
clear filter
0 4/10

Microsoft disclosed Storm-2561, a credential theft campaign that uses SEO poisoning to distribute digitally signed trojan VPN clients, tricking users searching for legitimate enterprise software into downloading malicious ZIP files from attacker-controlled websites.

Storm-2561 Microsoft
thehackernews.com · [email protected] (The Hacker News) · 8 hours ago · details
0 5/10

Threat actor Storm-2561 distributes fake VPN clients from major vendors (Ivanti, Cisco, Fortinet, Sophos, Sonicwall, Check Point, WatchGuard) via SEO poisoning to steal enterprise VPN credentials and configuration data. The malware bundle includes the Hyrax infostealer, creates persistence via RunOnce registry keys, and displays fake login interfaces before redirecting users to legitimate vendor sites to avoid detection.

Storm-2561 Hyrax Pulse.exe dwmapi.dll inspector.dll connectionsstore.dat Taiyuan Lihua Near Information Technology Co., Ltd. Microsoft GitHub Windows Defender SmartScreen
bleepingcomputer.com · Bill Toulas · 9 hours ago · details