# Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti VPN Clients for Credential Theft

> Storm-2561, tracked by Microsoft Threat Intelligence, conducts an ongoing SEO poisoning campaign that pushes trojanized Ivanti Pulse Secure VPN installers through manipulated Bing search results. The signed MSI installers deploy credential-stealing DLLs that exfiltrate VPN credentials to attacker-controlled C2 infrastructure, with historical correlation to Akira ransomware deployment.

- **Published:** 2026-03-12T12:00:00Z
- **Last reviewed:** 2026-03-12T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0218
- **ID:** TL-2026-0218
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** MONITORING
- **Actor:** Storm-2561 (Russia)
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Storm-2561 is a financially motivated threat actor tracked by Microsoft Threat Intelligence and Microsoft Defender Experts since late 2025. The group operates a sophisticated SEO poisoning campaign targeting enterprise users searching for legitimate VPN client software, specifically Ivanti Pulse Secure.

The attack chain begins with search engine manipulation. Storm-2561 registers convincing lookalike domains such as ivanti-pulsesecure.com (registered September 19, 2025) and ivanti-secure-access.org (registered September 14, 2025) and optimizes them to appear as top search results on Bing for queries like 'Ivanti Pulse Secure Download.' The campaign employs referrer-based conditional content delivery — serving benign content when pages are visited directly, but delivering malicious payloads when accessed via search engine referral.

Victims who click on the poisoned search results are redirected through intermediary domains (netml.shop, shopping5.shop) to a landing page that closely mimics the legitimate Ivanti download portal. The page offers a trojanized MSI installer file named 'Ivanti-VPN.msi' for download.

The trojanized installer is digitally signed with a certificate issued to 'Hefei Qiangwei Network Technology Co., Ltd.' by Certum Extended Validation Code Signing 2021 CA, signed on September 26, 2025 (valid through September 11, 2026, thumbprint EC443DE3ED3D17515CE137FE271C885B4F09F03E). The legitimate-looking code signature helps the malware bypass security controls and user suspicion.

Upon execution, the MSI installer deploys two malicious DLLs via DLL sideloading: dwmapi.dll (the sideloaded loader) and pulse_extension.dll (the credential-stealing payload). The malware targets the Ivanti VPN client's credential store at the hardcoded path C:\ProgramData\Pulse Secure\ConnectionStore\connectionstore.dat. It parses this file to extract the stored VPN server URI and associated authentication credentials.

The stolen credentials are exfiltrated via HTTP POST to a command-and-control server at 4.239.95.1:8080 (hosted on Microsoft Azure infrastructure) using the distinctive URI path /income_shit. The malware employs XOR-based deobfuscation during the C2 handshake to evade network-level detection.

This campaign is assessed as a precursor to ransomware operations. Threat intelligence correlation indicates that campaigns with these characteristics have historically preceded Akira ransomware deployment, where stolen VPN credentials enable initial network access, followed by lateral movement and eventual ransomware execution. The use of legitimate enterprise VPN credentials provides a high-value initial access vector that can bypass perimeter security controls.

The campaign has been active since at least September 2025 and continues to target enterprise users across multiple sectors as of March 2026.

## MITRE ATT&CK

- T1608.006 SEO Poisoning
- T1583.001 Domains
- T1583.003 Virtual Private Server
- T1588.003 Code Signing Certificates
- T1189 Drive-by Compromise
- T1204.002 Malicious File
- T1574.001 DLL
- T1553.002 Code Signing
- T1036.005 Match Legitimate Resource Name or Location
- T1140 Deobfuscate/Decode Files or Information
- T1555 Credentials from Password Stores
- T1552.001 Credentials In Files
- T1071.001 Web Protocols
- T1041 Exfiltration Over C2 Channel

## Sources

- [Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft](https://www.microsoft.com/en-us/security/blog/2026/03/12/storm-2561-uses-seo-poisoning-to-distribute-fake-vpn-clients-for-credential-theft/)
- [SEO Poisoning Targets Ivanti VPN: Credential Theft Alert](https://www.zscaler.com/blogs/security-research/spoofed-ivanti-vpn-client-sites)
- [Threat Actors Exploit Google Search with Fake Ivanti VPN Client Pages to Distribute Malware](https://cyberpress.org/fake-ivanti-vpn-malware/)
- [Akira Ransomware Exploits both SonicWall VPNs and Poisoned Search Results in Coordinated Campaigns](https://lmntrix.com/blog/akira-ransomware-exploits-both-sonicwall-vpns-and-poisoned-search-results-in-coordinated-campaigns/)
- [Subvert Trust Controls: Code Signing - MITRE ATT&CK T1553.002](https://attack.mitre.org/techniques/T1553/002/)
- [Compromised VPN Credentials Leading Attack Vector in Ransomware Campaigns](https://www.hipaajournal.com/compromised-credentials-vpn-leading-ransomware-attack-vector-q3-2025/)
- [Certum Extended Validation Code Signing Certificate Abuse](https://redcanary.com/blog/threat-detection/code-signing-certificates/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0218
