Threat reportMalwareTL-2026-0218
Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti VPN Clients for Credential Theft
Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti (TL-2026-0218), also tracked as Fake Ivanti VPN Campaign, is a high-severity malware campaign, first published 2026-03-12. It is attributed to Storm-2561 (Russia) with medium confidence, affects Ivanti Pulse Secure VPN Client, maps to 14 MITRE ATT&CK techniques (T1036.005, T1041, T1071.001), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 1Storm-2561
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-0218
- Threat ID
- TL-2026-0218
- Also known as
- Fake Ivanti VPN Campaign, Spoofed Ivanti Pulse Secure Campaign
- Severity
- HIGH
- Status
- MONITORING
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Storm-2561
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- enterprise, technology, financial, healthcare, government, education
- Target regions
- North America, Europe, Asia Pacific
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti
Malware and tooling: Win32_PWS_Agent
How Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti works
Storm-2561, tracked by Microsoft Threat Intelligence, conducts an ongoing SEO poisoning campaign that pushes trojanized Ivanti Pulse Secure VPN installers through manipulated Bing search results. The signed MSI installers deploy credential-stealing DLLs that exfiltrate VPN credentials to attacker-controlled C2 infrastructure, with historical correlation to Akira ransomware deployment.
Storm-2561 is a financially motivated threat actor tracked by Microsoft Threat Intelligence and Microsoft Defender Experts since late 2025. The group operates a sophisticated SEO poisoning campaign targeting enterprise users searching for legitimate VPN client software, specifically Ivanti Pulse Secure.
The attack chain begins with search engine manipulation. Storm-2561 registers convincing lookalike domains such as ivanti-pulsesecure.com (registered September 19, 2025) and ivanti-secure-access.org (registered September 14, 2025) and optimizes them to appear as top search results on Bing for queries like 'Ivanti Pulse Secure Download.' The campaign employs referrer-based conditional content delivery — serving benign content when pages are visited directly, but delivering malicious payloads when accessed via search engine referral.
Victims who click on the poisoned search results are redirected through intermediary domains (netml.shop, shopping5.shop) to a landing page that closely mimics the legitimate Ivanti download portal. The page offers a trojanized MSI installer file named 'Ivanti-VPN.msi' for download.
The trojanized installer is digitally signed with a certificate issued to 'Hefei Qiangwei Network Technology Co., Ltd.' by Certum Extended Validation Code Signing 2021 CA, signed on September 26, 2025 (valid through September 11, 2026, thumbprint EC443DE3ED3D17515CE137FE271C885B4F09F03E). The legitimate-looking code signature helps the malware bypass security controls and user suspicion.
Upon execution, the MSI installer deploys two malicious DLLs via DLL sideloading: dwmapi.dll (the sideloaded loader) and pulse_extension.dll (the credential-stealing payload). The malware targets the Ivanti VPN client's credential store at the hardcoded path C:\ProgramData\Pulse Secure\ConnectionStore\connectionstore.dat. It parses this file to extract the stored VPN server URI and associated authentication credentials.
The stolen credentials are exfiltrated via HTTP POST to a command-and-control server at 4.239.95.1:8080 (hosted on Microsoft Azure infrastructure) using the distinctive URI path /income_shit. The malware employs XOR-based deobfuscation during the C2 handshake to evade network-level detection.
This campaign is assessed as a precursor to ransomware operations. Threat intelligence correlation indicates that campaigns with these characteristics have historically preceded Akira ransomware deployment, where stolen VPN credentials enable initial network access, followed by lateral movement and eventual ransomware execution. The use of legitimate enterprise VPN credentials provides a high-value initial access vector that can bypass perimeter security controls.
The campaign has been active since at least September 2025 and continues to target enterprise users across multiple sectors as of March 2026.
MITRE ATT&CK techniques used in TL-2026-0218
defense-evasion
T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information
exfiltration
T1041 Exfiltration Over C2 Channel
command-and-control
initial-access
execution
credential-access
T1552.001 Credentials In Files; T1555 Credentials from Password Stores
defense-impairment
stealth
resource-development
T1583.001 Domains; T1583.003 Virtual Private Server; T1588.003 Code Signing Certificates; T1608.006 SEO Poisoning
Affected products and versions in Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti
Remediation for Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti
Immediate actions
- Block domains ivanti-pulsesecure.com, ivanti-secure-access.org, netml.shop, shopping5.shop at DNS/proxy level
- Block C2 IP 4.239.95.1 at perimeter firewall
- Hunt for dwmapi.dll and pulse_extension.dll in non-standard locations
- Scan endpoints for SHA256 c31af2c52dde677c33f8bd9e2a35c21ffd585e7c7b8e9981aa8c5afc89fed006
- Revoke and rotate VPN credentials for any users who may have downloaded VPN clients from unofficial sources
- Alert security team to monitor for unauthorized access using legitimate VPN credentials
Workarounds
- Distribute official Ivanti VPN clients through internal software distribution channels only
- Block MSI execution from user download directories via AppLocker or WDAC
- Restrict outbound HTTP connections to port 8080 from endpoints
Longer-term hardening
- Implement application whitelisting to prevent execution of unsigned or untrusted MSI installers
- Deploy EDR with DLL sideloading detection capabilities
- Enforce software download policies requiring IT-approved sources only
- Implement DNS sinkholing for known campaign infrastructure
- Deploy browser extensions or web proxies that warn on newly-registered domains
- Enable MFA on all VPN connections to mitigate credential theft impact
- Monitor for certificate thumbprint EC443DE3ED3D17515CE137FE271C885B4F09F03E in code signing events
Weaknesses (CWE) in Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti
Timeline of Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti
- Domain ivanti-secure-access.org registered by Storm-2561 operators
- Domain ivanti-pulsesecure.com registered by Storm-2561 operators
- Code signing certificate from Hefei Qiangwei Network Technology Co., Ltd. used to sign trojanized MSI installer via Certum EV CA
- Security researchers begin analyzing the fake Ivanti VPN installer campaign and identify credential-stealing behavior
- Zscaler ThreatLabz publishes technical analysis of spoofed Ivanti VPN client sites with IOCs and malware behavior details
- CyberPress reports on threat actors exploiting Google and Bing search results with fake Ivanti VPN client download pages
- LMNTRIX links SEO poisoning VPN campaigns to Akira ransomware deployment as a coordinated attack strategy
- Microsoft Threat Intelligence formally attributes the campaign to Storm-2561 and publishes comprehensive threat analysis
- As of 2026-05-29, Storm-2561 remains an operational financially-motivated actor and its SEO-poisoning/signed-trojan VPN-credential-theft technique is ongoing (no CVE, not KEV-relevant), per Microsoft and trade reporting through March 2026. However Microsoft took down the GitHub-hosted payloads and revoked the abused code-signing certificate, burning this threat's specific infrastructure, so it warrants MONITORING.
Sources cited for Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti
- Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
- SEO Poisoning Targets Ivanti VPN: Credential Theft Alert
- Threat Actors Exploit Google Search with Fake Ivanti VPN Client Pages to Distribute Malware
- Akira Ransomware Exploits both SonicWall VPNs and Poisoned Search Results in Coordinated Campaigns
- Subvert Trust Controls: Code Signing - MITRE ATT&CK T1553.002
- Compromised VPN Credentials Leading Attack Vector in Ransomware Campaigns
- Certum Extended Validation Code Signing Certificate Abuse
Detection coverage for TL-2026-0218
As of 2026-03-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0218 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.