Historical intelligence backfill. This assessment covers reporting originally published on 2026-03-12 and was added to the RWP archive on 2026-09-07.
Storm-2561's fake VPN clients turned "Pulse Secure download" into a credential form
SEO-poisoned results for enterprise VPN brands delivered signed MSI/DLL trojans that collected VPN logins, then sent users to the real vendor site so the failure looked like a bad installer.
Bottom line up front
CONFIRMED In mid-January 2026 Microsoft Defender Experts caught Storm-2561 SEO-poisoning searches such as "Pulse VPN download" / "Pulse Secure client" into GitHub-hosted ZIPs. The MSI sideloaded DLLs, popped a fake VPN GUI, exfiltrated credentials, persisted via RunOnce, then showed an install error and opened the real vendor download page. Brands spoofed in Microsoft/CSO reporting include Ivanti/Pulse, Fortinet, Cisco, SonicWall, Sophos, Check Point, WatchGuard. Actor active since at least May 2025. Signing cert from Taiyuan Lihua Near Information Technology Co., Ltd. was later revoked. Lookalike domains in the Microsoft post included vpn-fortinet[.]com and ivanti-vpn[.]org.
Historical backfill of 12 March 2026 reporting; added 7 September 2026.
What happened
Users trying to be secure downloaded a VPN from Google. GitHub plus a valid signature plus a familiar GUI beat "don't trust random EXEs." After theft, the real client works, so the victim never opens a ticket.
Why it mattered
Enterprise VPN credentials are network location. This is not a consumer adware story. Software acquisition via search is an unmanaged supply chain.
Who / what was affected
Anyone who installs remote-access clients from search, including contractors. OT: a plant technician doing the same thing is an IT credential incident that can become a jump-host incident — ASSESSED path, not a confirmed OT campaign.
Technical context
Controls: company portal only; block consumer GitHub MSI from user space if you can; DNS sinkhole of impersonation domains; alert on new VPN-looking processes that are not the packaged client. Revoked certs still need to be in your allow-list logic.
Exploitation / threat status at the time
CONFIRMED campaign, brands, GitHub hosting, error-then-real-site trick.
REPORTED GitHub repos removed after notice.
What defenders should have done
- Official package source for Ivanti/Fortinet/Cisco clients; document it.
- Hunt RunOnce VPN names and the revoked publisher.
- Assume captured VPN creds are live; rotate, require cert-based or SAML VPN.
RWP assessment
Confidence: High on Microsoft's chain. This is search-bar initial access.
Defensive actions
- Intune/Company Portal as the only VPN installer.
- User comms: never Google the client name.
- Rotate VPN secrets if this could have hit help desk.
Sources
- Microsoft Threat Intelligence — Storm-2561 uses SEO poisoning to distribute fake VPN clients
- SecurityWeek — Threat actor targeting VPN users in credential theft campaign
- CSO Online — Storm-2561 targets enterprise VPN users with SEO poisoning