Storm-2561 is relying on SEO poisoning to distribute fake VPN clients that install trojans and steal users’ credentials.
Storm-2561 spreads fake VPN installers via SEO poisoning and GitHub downloads, stealing enterprise VPN credentials with Hyrax malware.
The financially motivated group has been active since May 2025, impersonating Fortinet, Ivanti, Cisco, and other vendors to steal corporate credentials.
Cryptopolitan on MSN
Etherscan warns users after a victim receives 89 address-poisoning emails
Etherscan has issued a warning to users after a victim received 89 address-poisoning emails in under 30 minutes following ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results