Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft

2026-03-15T20:52:19Z50b2c16dff3baeda0620aedca2e6a27ee0235883a106c8ed73d48591866ff8a8
AI operationalizationAiTMContagious InterviewFlexibleFerretIOCsLLM chat harvestingMicrosoft Security BlogOtterCookieRMM backdoorSEO poisoningStorm-2561Tycoon2FAcredential theftfake VPNmalicious browser extensionsmitigationsphishing-as-a-serviceprompt injectionsigned trojanstolen EV certificate

What happened

This Microsoft Security Blog feed highlights multiple active campaigns and threats: Storm-2561 uses SEO poisoning to push fake VPN clients that install signed trojans and harvest VPN credentials by mimicking trusted brands and abusing legitimate services; Contagious Interview targets developers with fake job interviews delivering backdoors (OtterCookie, FlexibleFerret) to steal API tokens, cloud credentials, wallets, and source code; Tycoon2FA is a large-scale AiTM/PhaaS phishing platform (affecting hundreds of thousands of organizations) that was disrupted by law enforcement and partners; a恶意

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
50b2c16dff3baeda0620aedca2e6a27ee0235883a106c8ed73d48591866ff8a8
Enrichment time
2026-03-15T20:52:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.