This technique is not limited to a single group. Multiple threat actors ranging from financially motivated cybercrime groups to initial access brokers are actively abusing SEO poisoning and fake VPN installers to gain footholds in enterprise environments.
1. Storm-2561
Storm-2561 is a financially motivated cybercrime group active since at least May 2025, primarily targeting enterprise users in North America and Europe. The group specializes in credential theft and initial access operations, often enabling downstream ransomware activity. In early 2026, Storm-2561 leveraged SEO poisoning to distribute trojanized enterprise VPN clients, including spoofed versions of Pulse Secure, Ivanti, and Fortinet. Their operations relied heavily on trusted platforms such as GitHub to host payloads, combined with digitally signed malware to bypass security controls. The group’s ability to blend social engineering with supply-chain-like delivery makes it particularly effective in targeting users actively searching for remote access tools.
2. Silver Fox (Void Arachne)
Silver Fox, also known as Void Arachne, is a China-based threat group active since around 2022, initially focused on financially motivated campaigns but increasingly overlapping with espionage-style operations. The group primarily targets Chinese-speaking regions, including China, Taiwan, and Southeast Asia, but has shown signs of expanding its reach globally. Silver Fox has incorporated SEO poisoning into its distribution strategy, using fake software portals including VPN and AI tools to deliver malware such as ValleyRAT. These campaigns often rely on cloud-hosted payloads and regionally tailored lures, allowing the group to maintain both scale and stealth while targeting users attempting to bypass network restrictions or access restricted services.
3. Exotic Lily
Exotic Lily is a financially motivated cybercrime group first identified around 2023 and closely associated with ransomware affiliate ecosystems, including links to operations such as Conti. The group is known for large-scale initial access campaigns using phishing, SEO poisoning, and malicious advertising to distribute trojanized enterprise software. While not exclusively focused on VPNs, Exotic Lily has abused search-driven distribution to deliver fake installers for enterprise tools including VPN clients, remote access software, and collaboration platforms often embedding the Bumblebee payload. Their operations are designed for scale, enabling them to compromise a high volume of organizations and sell access to other threat actors.
4. WikiLoader Campaigns and Initial Access Brokers (IABs)
Campaigns involving WikiLoader (also known as WailingCrab) are typically attributed to loosely organized initial access brokers rather than a single named actor. These operators specialize in gaining initial footholds in enterprise networks and monetizing that access. In 2024, SEO poisoning campaigns impersonating Palo Alto GlobalProtect VPN software were used to deliver trojanized installers that sideloaded WikiLoader. Once executed, the malware established communication with attacker-controlled infrastructure and enabled delivery of secondary payloads such as DanaBot. These campaigns targeted sectors such as education and transportation in the United States, demonstrating how VPN-themed SEO poisoning can be operationalized as a scalable access vector.
5. Unknown Actors – Trojanized VPN Ecosystem
In addition to tracked groups, multiple unattributed actors have conducted similar campaigns targeting VPN software. Examples include trojanized versions of SonicWall NetExtender and fake Fortinet VPN portals observed between 2025 and 2026. These operations typically follow the same pattern: spoofed vendor websites, credential harvesting prior to download, and delivery of modified or backdoored installers. While attribution remains unclear, the consistency of techniques suggests a growing ecosystem where fake VPN distribution is becoming a standardized method for credential theft and initial access.