Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft

2026-03-13T02:52:27Z22fdaa5d72282f6c5afbda52dcb8409024c90d98c63e7b5098f2c561bef10292
ai-as-tradecraftaitmcoral-sleetcredential-theftdeveloper-targetingfake-vpnflexibleferretiocjasper-sleetjob-interview-luresllm-data-exfiltrationmalicious-browser-extensionsmitigationnorth-korean-actorsottercookiephishing-as-a-serviceprompt-abuseprompt-injectionrmm-backdoorseo-poisoningsigned-malwarestolen-ev-certificatesupply-chain-abusetycoon2fa

What happened

Microsoft Security Blog posts describe multiple active, high-impact campaigns and tradecraft trends: Storm-2561 uses SEO poisoning to push fake VPN clients that install signed trojans to steal VPN credentials and mimic trusted brands; signed malware using stolen EV certificates deployed legitimate RMM tools to achieve persistent access; Tycoon2FA (an AiTM PhaaS) operated at scale enabling widespread credential theft; malicious AI browser extensions harvested LLM chat histories and browsing data with ~900,000 installs affecting >20,000 enterprise tenants; the “Contagious Interview” campaign l l

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
22fdaa5d72282f6c5afbda52dcb8409024c90d98c63e7b5098f2c561bef10292
Enrichment time
2026-03-13T02:52:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft · Baitaphish