Storm-2561Storm-2561

Also known as: Storm-2561

Known aliases
1

Profile

Storm-2561 is a cybercriminal threat actor known for a credential theft campaign that employs SEO poisoning to distribute fake VPN clients. The campaign redirects users to malicious ZIP files containing digitally signed trojans that harvest VPN credentials, leveraging user trust in search engine results. The malicious components are signed by “Taiyuan Lihua Near Information Technology Co., Ltd.” and were hosted on GitHub repositories that have since been taken down. This operation exhibits characteristics consistent with financially motivated cybercrime.

Aliases· 1

Storm-2561

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Storm-0558
Actor
Storm Cloud
Actor
UNC2565
Actor
UNC6691
Actor
TA2541
Actor
Storm-0062
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.