Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
2026-03-14T14:52:20Z•0ce6b3d098661ca84718ba6b9a31cf8b3fbac5b72b7608dae455c41df135253e
IOCsaitmcode-signingcredential-theftev-certificatefake-vpnjob-recruitment-luresllm-data-exfiltrationmalicious-browser-extensionsmalwaremitigation-guidancephishingphishing-as-a-serviceremote-monitoring-and-managementrmm-backdoorseo-poisoningsupply-chain-impersonationtrojantycoon2fa
What happened
This Microsoft Security Blog feed highlights multiple active, high-impact threats: Storm-2561’s SEO-poisoning campaign distributing fake VPN clients that install signed trojans to harvest VPN credentials (active since 2025 and mimicking trusted brands); malware delivered via fake developer job interviews (OtterCookie, FlexibleFerret) that steal API tokens, cloud credentials, wallets, and source code; large-scale malicious browser extensions that exfiltrate LLM chat histories and browsing data (nearly 900k installs, affecting >20k enterprise tenants); Tycoon2FA AiTM phishing-as-a-service at web
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 0ce6b3d098661ca84718ba6b9a31cf8b3fbac5b72b7608dae455c41df135253e
- Enrichment time
- 2026-03-14T14:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.