What looks like a legit VPN download could be a trap, as SEO poisoning is being used to steal corporate logins.
The malware is designed to steal the victim’s VPN login credentials. According to Microsoft, the attack uses search engine optimization (SEO) poisoning to push websites hosting the malicious VPN ...
A new malware has been identified by cybersecurity researchers, and it is capable of many information gathering techniques like screen capture, audio capture, remote shell (which permits the threat ...
Storm-2561 uses SEO poisoning to push fake VPN downloads that install signed trojans and steal VPN credentials. Active since 2025, Storm-2561 mimics trusted brands and abuses legitimate services. This ...
Storm-2561 spreads fake VPN installers via SEO poisoning and GitHub downloads, stealing enterprise VPN credentials with Hyrax malware.