Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft

2026-03-15T02:52:17Z2ca23e86958ac24641ef85bc3d6d922162702e38b2977345d46aa4c8c04c2e18
AiTM phishingFlexibleFerretIoCsLLM data exfiltrationNorth KoreaOtterCookieRMM backdoorSEO poisoningTycoon2FAcredential theftdeveloper-targetingfake VPNmalicious browser extensionsmitigation guidancephishing-as-a-serviceprompt injectionsigned malwaresocial engineeringstolen EV certificatethreat actor Storm-2561

What happened

Microsoft Security Blog items (Mar 2026) highlight multiple active campaigns and tradecraft trends: Storm-2561 is using SEO poisoning to push fake VPN clients that install signed trojans and steal VPN credentials (campaign active since 2025, mimics trusted brands and abuses legitimate services). Other reports cover large-scale AiTM/phishing infrastructure (Tycoon2FA), malicious AI browser extensions exfiltrating LLM chat histories at scale, developer-targeted recruitment lures delivering backdoors (OtterCookie, FlexibleFerret), signed malware abusing stolen EV certificates to deploy RMM back-­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
2ca23e86958ac24641ef85bc3d6d922162702e38b2977345d46aa4c8c04c2e18
Enrichment time
2026-03-15T02:52:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.