Storm-2561 is a financially motivated cybercriminal threat actor tracked by Microsoft since May 2025. The actor is known for SEO poisoning and brand impersonation campaigns that redirect users searching for legitimate enterprise software to spoofed download pages and attacker-controlled hosting, including abuse of legitimate services. A core tradecraft pattern is the distribution of trojanized VPN and other enterprise software installers that appear trustworthy, including digitally signed payloads, in order to steal credentials and establish footholds while reducing user suspicion. Storm-2561 has been associated with fake VPN client campaigns targeting enterprise remote-access users. In these operations, victims are lured through manipulated search results and fraudulent software-branding themes, then delivered signed trojans that sideload malicious components and present convincing fake login interfaces to capture VPN credentials. Reported malware used by the actor includes credential-stealing payloads such as a Hyrax variant and earlier delivery of the Bumblebee loader. Observed behaviors include credential theft, persistence, DLL sideloading, and defense evasion through code signing and masquerading as trusted software. Storm-2561 has also been linked to the use of malware signed through the Fox Tempest malware-signing-as-a-service ecosystem. That relationship places the actor among criminal operators that leveraged fraudulently obtained short-lived code-signing certificates to make malicious binaries appear legitimate and improve delivery success. Fox Tempest-linked activity involving Storm-2561 has been associated with malware delivery through malvertising, fake advertisements, and SEO poisoning. The actor’s operations are consistent with cybercrime focused on monetizable access and stolen credentials rather than espionage. Storm-2561 is best characterized as an initial-access and credential-theft actor that relies heavily on search-result manipulation, software impersonation, signed malware, and user deception to compromise victims.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
31 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named by Microsoft as a threat group that utilized malware signed through Fox Tempest's fraudulent signing service.
Named as a customer of Fox Tempest's malware-signing service.
Named as a threat actor linked to the Fox Tempest malware-signing service.
Named activity cluster observed using Fox Tempest-signed malware in real-world intrusions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.