Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
2026-03-13T08:52:23Z•540e09311765edb5e20a45d22f14f4cb309a02eb82a00bdfbf490ccc7f3e7cce
AI operationalizationAiTM phishingCoral SleetFlexibleFerretIOCsJasper SleetLLM data exfiltrationNorth Korean groupsOtterCookieRMM backdoorsSEO poisoningStorm-2561Tycoon2FAcredential theftfake VPNjob-interview luremalicious browser extensionsmitigationsphishing-as-a-serviceprompt injectionsigned malwarestolen EV certificate
What happened
Microsoft Security Blog (Mar 2026) documents multiple active campaigns and TTPs that result in credential theft, persistent access, and large-scale data exposure. Storm-2561 uses SEO poisoning to distribute fake VPN clients that install signed trojans and steal VPN credentials while impersonating trusted brands and abusing legitimate services. Other notable activity includes malware delivered via fake developer job interviews (OtterCookie, FlexibleFerret) to steal API tokens, cloud credentials, crypto wallets, and source code; Tycoon2FA (AiTM phishing-as-a-service) operating at scale; signed-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 540e09311765edb5e20a45d22f14f4cb309a02eb82a00bdfbf490ccc7f3e7cce
- Enrichment time
- 2026-03-13T08:52:23Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.