Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft

2026-03-15T14:52:22Z333c356d8d353527da801f70d55889feee03d9799cbde2ae33549996eae81134
AiTMEV certificateFlexibleFerretIOCsLLM data exfiltrationOtterCookieRMM backdoorSEO poisoningTycoon2FAcredential theftfake VPNjob-interview luremalicious browser extensionsmitigationphishingprompt injectionsigned malwarethreat actor tradecraft

What happened

Microsoft Security Blog roundup covering multiple active campaigns and trends: Storm-2561 (active since 2025) uses SEO poisoning to push fake VPN clients that install signed trojans and steal VPN credentials while mimicking trusted brands and abusing legitimate services; signed malware using stolen EV certificates has been used to deploy legitimate RMM tooling for persistent access; Tycoon2FA is a large-scale AiTM/PhaaS phishing platform; malicious AI browser extensions harvested LLM chat histories and browsing data at scale (~900k installs, >20k enterprise tenants); “Contagious Interview” l‑a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
333c356d8d353527da801f70d55889feee03d9799cbde2ae33549996eae81134
Enrichment time
2026-03-15T14:52:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft · Baitaphish