Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
2026-03-15T08:52:25Z•19041d6edec7967f0db3b33c582d5b7826f2f44f8cd3e543d43147bad8ee8894
AI operationalizationAiTM phishingContagious InterviewFlexibleFerretLLM data exfiltrationOtterCookieRMM backdoorsSEO poisoningStorm-2561Tycoon2FAcredential theftenterprise compromisefake VPN clientsmalicious browser extensionsphishing-as-a-serviceprompt injectionsigned malwarestolen EV certificatesupply-chain impersonation
What happened
Microsoft Security Blog posts summarize multiple active campaigns and trends: Storm-2561 (active since 2025) uses SEO poisoning to push fake VPN clients that install signed trojans and steal VPN credentials while mimicking trusted brands and abusing legitimate services. Other notable items include malicious AI browser extensions (≈900,000 installs) harvesting LLM chat histories across many enterprise tenants; the Tycoon2FA AiTM phishing-as-a-service platform impacting ~500,000 organizations monthly; targeted “Contagious Interview” deliveries of backdoors (OtterCookie, FlexibleFerret) to steal云
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 19041d6edec7967f0db3b33c582d5b7826f2f44f8cd3e543d43147bad8ee8894
- Enrichment time
- 2026-03-15T08:52:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.