Threat actors are using software impersonation and SEO poisoning to push victims toward fake download sites for trusted enterprise and IT tools, then delivering malware through trojanized installers. In one campaign, Storm-2561 used spoofed VPN vendor pages for products such as Pulse Secure, Fortinet, and Ivanti to steal enterprise VPN credentials. The malicious packages were hosted on GitHub, signed with a certificate issued to "Taiyuan Lihua Near Information Technology Co., Ltd.", and designed to show an error before redirecting victims to the legitimate vendor site, reducing suspicion while exfiltrating credentials.
A separate but closely related campaign used fake FileZilla download pages to distribute a Remote Access Trojan through multi-stage loaders and DLL sideloading. Attackers bundled legitimate FileZilla software with a malicious version.dll, or dropped the DLL during installation so the malware would execute while the expected application appeared to install normally. Both reports describe the same broader intrusion pattern: adversaries abusing trusted brands, realistic lookalike websites, and legitimate software packaging to compromise users who believe they are downloading authentic tools. A separate Warlock intrusion analysis describing web shells, lateral movement, tunneling, and ransomware activity is a different incident and does not match this malware-delivery story.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Attackers impersonated Foxit PDF Reader with trojanized installer packages that masqueraded as legitimate software downloads. The fake installer deployed UltraVNC to establish stealthy remote access on compromised systems, reflecting a software-impersonation and social-engineering malware campaign.
Gurucul disclosed an SEO-poisoning campaign redirecting users searching for TestDisk to the spoofed domain testdisk[.]dev, where a fake PhotoRec installer delivered a ZIP containing a renamed Microsoft Setup binary that side-loaded a malicious autorun.dll. The multi-stage infection ultimately installed legitimate TestDisk software alongside a trojanized ScreenConnect client for persistent remote access, and the report published related IOCs including domain, URL, IP 193.42.11.108, and a SHA-256 hash.
A forensic investigation found that a user downloaded and ran a fake Sysinternals executable from a malicious website, leading to a trojan and information stealer infection. Analysis showed the malware stole user input and browser session cookies, contacted command-and-control infrastructure, and dropped a second-stage payload named vmtoolsIO.exe that established persistence via the VMwareIOHelperService auto-start service.
Investigators uncovered a long-running campaign active since October 2025 that used fake download pages for more than 25 popular applications to deliver ZIP archives containing legitimate software and malicious DLL sideloading components. The infection chain silently installed ScreenConnect and ultimately deployed an AsyncRAT variant with credential theft, keylogging, clipboard monitoring, and cryptocurrency clipper capabilities.
Microsoft publicly identified Storm-2561 as behind an ongoing credential theft operation that used SEO poisoning and spoofed VPN software sites to target enterprise users. The disclosure highlighted the risk of stolen VPN access enabling lateral movement, data theft, and follow-on attacks across industries and regions.
Analysis revealed the RAT supports credential theft, keylogging, screenshot capture, and hidden remote control through HVNC. The malware also used anti-VM and anti-sandbox checks and communicated with the command-and-control domain welcome.supp0v3.com via DNS-over-HTTPS through Cloudflare's 1.1.1.1 resolver.
EST Security analysts identified an active campaign using fake websites impersonating the official FileZilla download page to infect Windows users. The attackers bundled legitimate FileZilla software with a malicious DLL and used DLL sideloading plus a multi-stage in-memory loader to deploy a remote access trojan.
eSentire disclosed a multi-stage malware campaign observed in March 2026 that used SEO poisoning and fake Chinese-language software sites for tools including FinalShell, Xshell, QuickQ, and Clash to deliver Kong RAT. The campaign targeted Chinese-speaking developers and IT professionals and used Alibaba Cloud OSS infrastructure, DLL sideloading, shellcode execution, and a COM UAC bypass for post-compromise control.
Blackpoint SOC reported a campaign using SEO poisoning and malvertising to lure users searching for Microsoft Teams to spoofed download sites serving trojanized installers such as MSTeamsSetup.exe. The installer deployed the Oyster (Broomstick) backdoor, established persistence with a scheduled task named CaptureService, and used signed binaries and spoofed domains to appear legitimate.
In the campaign, attackers distributed fake MSI installers that dropped legitimate-looking executables and malicious DLLs, including a Hyrax infostealer variant, to steal VPN credentials and configuration data. Microsoft found the malware was signed with a certificate issued to Taiyuan Lihua Near Information Technology Co., Ltd., which was later revoked.
Microsoft said the financially motivated Storm-2561 campaign has been active since at least May 2025, using SEO manipulation to lure enterprise users to spoofed VPN software sites. The actor impersonated brands including Pulse Secure, Fortinet, Ivanti, GlobalProtect, and Sophos Connect to distribute malicious ZIP packages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
infosec.pub
Open sourceesentire.com
Open sourcecommunity.gurucul.com
Open sourcehackers-arise.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourceblackpointcyber.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.