Cybercrime Actors Exploit VPN Trust Through SEO Poisoning To Steal Enterprise Credentials

Searching for software online is one of the most common actions performed in any enterprise environment. Whether it is a VPN client, remote access tool, or productivity application, employees often rely on search engines to quickly find what they need to continue their work.

This behavior is now being actively exploited.

Recent threat intelligence highlights a growing campaign, tracked as Storm-2561, where threat actors use SEO poisoning techniques to place malicious VPN installers at the top of search results. Instead of relying on phishing emails or malicious attachments, these attacks begin with a legitimate user action: searching for software.

Once executed, these installers provide attackers with initial access, allowing credential harvesting, persistence, and further lateral movement inside enterprise environments.

Threat Overview

Storm-2561 is a financially motivated cybercrime group active since at least May 2025, primarily targeting enterprise users in North America and Europe. The group focuses on credential theft and initial access operations, often enabling downstream ransomware activity.

In early 2026, the group conducted a large-scale campaign abusing SEO poisoning to target users searching for enterprise VPN software such as:

  • Pulse Secure
  • Ivanti
  • Fortinet

Attackers created spoofed websites and ensured they ranked highly in search results. When victims clicked these links, they were redirected to attacker-controlled infrastructure, often hosted on legitimate platforms such as GitHub.

Attack Flow

The attack chain is simple but highly effective:

  1. A user searches for a VPN client
  2. A malicious website appears among the top search results
  3. The user downloads a seemingly legitimate installer
  4. The installer executes and deploys malware in the background
  5. Persistence mechanisms are established
  6. Credentials and system data are collected
  7. Data is exfiltrated to attacker-controlled infrastructure

This entire process happens without phishing emails or obvious warning signs, making detection more difficult.

Key Techniques

The campaign relies on a combination of trust abuse and technical evasion:

  • SEO Poisoning: Malicious domains are optimized to rank above legitimate vendor sites
  • Signed Malware: Installers are signed using valid or stolen certificates to appear legitimate
  • DLL Sideloading: Malicious DLLs are loaded through legitimate executables
  • Credential Harvesting: VPN credentials and stored secrets are extracted from infected systems
  • Persistence Mechanisms: Registry keys, scheduled tasks, or startup entries ensure continued access
  • Cloud Hosting Abuse: Payloads and infrastructure are hosted on trusted platforms to avoid detection

Payload and Impact

The core payload in this campaign is a variant of the Hyrax infostealer, deployed as inspector.dll. Hyrax is purpose-built for VPN credential theft, it extracts stored VPN configuration data and credentials and exfiltrates them to attacker-controlled C2 infrastructure at 194.76.226[.]93:8080.

Microsoft Defender Antivirus detects payloads associated with this campaign under signatures in the Trojan:Win32/Malgent family.

This payload enables attackers to:

  • Steal enterprise VPN access
  • Maintain persistence
  • Sell access to other threat actors (e.g., ransomware groups)

How SEO Poisoning Enables Fake VPN Attacks

SEO poisoning is central to the success of this campaign.

Instead of pushing malicious content toward victims, attackers wait for victims to come to them.

How It Works

  • Attackers create domains that closely resemble legitimate vendors
  • Search engine optimization techniques boost visibility
  • Users searching for software unknowingly click malicious links
  • Trust is established before any malicious action occurs

 

Why It Is Effective

  • Users trust search engine results
  • No phishing email is required
  • The workflow feels normal and expected
  • HTTPS and branding reduce suspicion
  • Security controls focused on email or attachments are bypassed

This makes SEO poisoning a reliable initial access technique.

Threat Actors Behind Fake VPN SEO Campaigns

This technique is not limited to a single group. Multiple threat actors ranging from financially motivated cybercrime groups to initial access brokers are actively abusing SEO poisoning and fake VPN installers to gain footholds in enterprise environments.

 

1. Storm-2561

Storm-2561 is a financially motivated cybercrime group active since at least May 2025, primarily targeting enterprise users in North America and Europe. The group specializes in credential theft and initial access operations, often enabling downstream ransomware activity. In early 2026, Storm-2561 leveraged SEO poisoning to distribute trojanized enterprise VPN clients, including spoofed versions of Pulse Secure, Ivanti, and Fortinet. Their operations relied heavily on trusted platforms such as GitHub to host payloads, combined with digitally signed malware to bypass security controls. The group’s ability to blend social engineering with supply-chain-like delivery makes it particularly effective in targeting users actively searching for remote access tools.

 

2. Silver Fox (Void Arachne)

Silver Fox, also known as Void Arachne, is a China-based threat group active since around 2022, initially focused on financially motivated campaigns but increasingly overlapping with espionage-style operations. The group primarily targets Chinese-speaking regions, including China, Taiwan, and Southeast Asia, but has shown signs of expanding its reach globally. Silver Fox has incorporated SEO poisoning into its distribution strategy, using fake software portals including VPN and AI tools to deliver malware such as ValleyRAT. These campaigns often rely on cloud-hosted payloads and regionally tailored lures, allowing the group to maintain both scale and stealth while targeting users attempting to bypass network restrictions or access restricted services.

 

3. Exotic Lily

Exotic Lily is a financially motivated cybercrime group first identified around 2023 and closely associated with ransomware affiliate ecosystems, including links to operations such as Conti. The group is known for large-scale initial access campaigns using phishing, SEO poisoning, and malicious advertising to distribute trojanized enterprise software. While not exclusively focused on VPNs, Exotic Lily has abused search-driven distribution to deliver fake installers for enterprise tools including VPN clients, remote access software, and collaboration platforms often embedding the Bumblebee payload. Their operations are designed for scale, enabling them to compromise a high volume of organizations and sell access to other threat actors.

 

4. WikiLoader Campaigns and Initial Access Brokers (IABs)

Campaigns involving WikiLoader (also known as WailingCrab) are typically attributed to loosely organized initial access brokers rather than a single named actor. These operators specialize in gaining initial footholds in enterprise networks and monetizing that access. In 2024, SEO poisoning campaigns impersonating Palo Alto GlobalProtect VPN software were used to deliver trojanized installers that sideloaded WikiLoader. Once executed, the malware established communication with attacker-controlled infrastructure and enabled delivery of secondary payloads such as DanaBot. These campaigns targeted sectors such as education and transportation in the United States, demonstrating how VPN-themed SEO poisoning can be operationalized as a scalable access vector.

 

5. Unknown Actors – Trojanized VPN Ecosystem

In addition to tracked groups, multiple unattributed actors have conducted similar campaigns targeting VPN software. Examples include trojanized versions of SonicWall NetExtender and fake Fortinet VPN portals observed between 2025 and 2026. These operations typically follow the same pattern: spoofed vendor websites, credential harvesting prior to download, and delivery of modified or backdoored installers. While attribution remains unclear, the consistency of techniques suggests a growing ecosystem where fake VPN distribution is becoming a standardized method for credential theft and initial access.

Impacted Technologies

  • Windows endpoints
  • Enterprise VPN solutions
  • Web browsers and search engines
  • Credential storage mechanisms
  • Corporate network access infrastructure

Detection and Defense

  • From a SOC Perspective
    Focus on behavioral signals rather than initial delivery:

    • Monitor execution of installers from browser download paths
    • Detect unusual parent-child process chains involving VPN installers
    • Identify outbound connections immediately following installation
    • Track suspicious use of signed binaries from unknown sources
    • Investigate new persistence mechanisms after software installation
  • From a Security Controls Perspective
    • Enforce application allowlisting for approved software
    • Restrict installation of unauthorized VPN clients
    • Monitor DNS and web traffic for lookalike domains
    • Validate digital certificates rather than trusting them blindly
    • Apply endpoint protection to detect DLL sideloading behavior
  • From a User Awareness Perspective
    • Download software only from verified vendor websites
    • Avoid relying solely on search engine results
    • Be cautious of sponsored or top-ranked links
    • Verify URLs carefully before downloading
    • Report unusual behavior after software installation

Why This Is Important

This attack technique represents a shift in how initial access is obtained.

There is no phishing email. No malicious attachment. No obvious trigger.

The compromise begins with:

  • a normal search
  • a trusted-looking website
  • a legitimate-looking installer

This changes the detection challenge significantly.

Key risks include:

  • Silent initial access into enterprise environments
  • Immediate credential exposure
  • Bypassing traditional email-based defenses
  • Increased likelihood of user execution due to trust

Because the activity looks legitimate at every stage, organizations may not detect the compromise until later phases such as lateral movement or data exfiltration.

How Wizard Cyber Can Help Important

Wizard Cyber supports organizations in detecting and mitigating threats such as SEO-based malware campaigns through:

  • Continuous threat intelligence monitoring of emerging campaigns
  • Detection engineering aligned with Microsoft Defender XDR and Sentinel
  • Threat hunting for suspicious software execution and persistence activity
  • Awareness programs focused on modern attack techniques
  • Incident response support for compromised endpoints
CYBERSECURITY READINESS

Strengthen Your Cyber Defences Today

As cyber threats grow more complex, proactive detection is no longer optional.

With Wizard Cyber’s Microsoft expertise, organizations can transform their security posture and gain real-time visibility across all endpoints.

Start your journey to smarter, faster cybersecurity today.

EXPLORE MORE

Related Blogs & Insights

Discover blogs that deepen your knowledge and accelerate your security strategy.

ABOUT THE AUTHOR
Mohammad AlShahwan
SOC Analyst Level 1

Mohammad specialises in cyber security innovation, security operations, and research into emerging cyber threats. He contributes to developing advanced security capabilities and operational improvements within the SOC. He holds Microsoft SC-200, AZ-500, and SC-300 certifications

 

Certifications: SC-200, AZ-500, SC-300

Cyber Shield Intelligence (CSI) Team

Cyber Shield Intelligence (CSI) Team

Wizard Cyber’s first line of defense in proactive threat intelligence. CSI is dedicated to the identification, monitoring, and analysis of emerging cyber threats, including activity across the dark web, underground forums, and threat actor infrastructure. Leveraging advanced threat intelligence platforms, OSINT tools, and adversary tracking methodologies, the team provides actionable intelligence to anticipate attacks before they occur. With expertise in threat actor profiling, TTP mapping (aligned with the MITRE ATT&CK framework), and IOC enrichment, CSI equips clients with the critical insights needed to fortify defenses, mitigate risk, and stay ahead of evolving threat landscapes.

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation