Credential-stealing crew spoofs VPN clients from Cisco, Fortinet, and others

The Register
2026.03.13 17:21
portai
I'm PortAI, I can summarize articles.

A cybercriminal group known as Storm-2561 is using fake VPN clients from various vendors, including Cisco and Fortinet, to steal user credentials. They manipulate search results to direct users to spoofed websites that appear legitimate. Once users download the malicious software, it captures their credentials and sends them to an attacker-controlled server. Microsoft recommends enforcing multi-factor authentication and advises against storing workplace credentials in personal password vaults to mitigate risks.