Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft

2026-03-16T08:52:21Z142d857eba8e322f3249c3e6e7ad75e0ba9440f4b9410675f205aa874d0a2c1c
aitm-phishingcredential-theftdeveloper-targetingev-certificate-theftfake-vpnllm-data-exfiltrationmalicious-browser-extensionsrmm-backdoorseo-poisoningsigned-malwaresocial-engineeringstorm-2561supply-chain-deceptiontycoon2fa

What happened

Microsoft Security Blog (March 2026) documents multiple active high-impact campaigns and trends: Storm-2561 uses SEO poisoning to push fake VPN clients that install signed trojans to harvest VPN credentials and impersonate trusted brands; Tycoon2FA is an AiTM/phishing-as-a-service platform operating at scale; a “Contagious Interview” campaign delivers backdoors (OtterCookie, FlexibleFerret) via fake developer job interviews to steal API tokens, cloud credentials, wallets, and source code; malicious AI browser extensions collected LLM chat histories and browsing data at scale across many tenant

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
142d857eba8e322f3249c3e6e7ad75e0ba9440f4b9410675f205aa874d0a2c1c
Enrichment time
2026-03-16T08:52:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft · Baitaphish