Storm-2561 Fake VPN Client Activity
This query detects multiple TTPs associated with the Storm-2561 campaign that uses SEO poisoning to distribute fake VPN clients for credential theft. It looks for known file hashes, a specific code-signing certificate, malicious DLL side-loading and C2 communication patterns.
Microsoft Sentinel (KQL)

