Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
2026-03-15T02:52:17Z•2ca23e86958ac24641ef85bc3d6d922162702e38b2977345d46aa4c8c04c2e18
AiTM phishingFlexibleFerretIoCsLLM data exfiltrationNorth KoreaOtterCookieRMM backdoorSEO poisoningTycoon2FAcredential theftdeveloper-targetingfake VPNmalicious browser extensionsmitigation guidancephishing-as-a-serviceprompt injectionsigned malwaresocial engineeringstolen EV certificatethreat actor Storm-2561
What happened
Microsoft Security Blog items (Mar 2026) highlight multiple active campaigns and tradecraft trends: Storm-2561 is using SEO poisoning to push fake VPN clients that install signed trojans and steal VPN credentials (campaign active since 2025, mimics trusted brands and abuses legitimate services). Other reports cover large-scale AiTM/phishing infrastructure (Tycoon2FA), malicious AI browser extensions exfiltrating LLM chat histories at scale, developer-targeted recruitment lures delivering backdoors (OtterCookie, FlexibleFerret), signed malware abusing stolen EV certificates to deploy RMM back-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 2ca23e86958ac24641ef85bc3d6d922162702e38b2977345d46aa4c8c04c2e18
- Enrichment time
- 2026-03-15T02:52:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.