Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft

2026-03-14T20:52:19Z5d96858c042f63bfccae2096166203d4b195bdeefc5d8edbc942e9d923c50e8f
AI-enabled tradecraftAiTMContagious InterviewFlexibleFerretLLM data exfiltrationNorth Korean groupsOtterCookieRMM backdoorSEO poisoningStorm-2561Tycoon2FAcredential theftfake VPNmalicious browser extensionsphishing-as-a-serviceprompt injectionsigned malwaresigned trojanstolen EV certificatesupply chain abusethreat actor tradecraft

What happened

This set of Microsoft Security Blog posts describes multiple active, high-impact campaigns and evolving tradecraft. Highlights: Storm-2561 uses SEO poisoning to push fake VPN clients that install signed trojans and steal VPN/VPN-credential data; a recruitment-themed “Contagious Interview” campaign delivers developer-focused backdoors (OtterCookie, FlexibleFerret) to harvest API tokens, cloud credentials, wallets, and source code; malicious AI browser extensions exfiltrated LLM chat histories and browsing data at scale (≈900k installs, >20k enterprise tenants); Tycoon2FA remains a large AiTM/P

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
5d96858c042f63bfccae2096166203d4b195bdeefc5d8edbc942e9d923c50e8f
Enrichment time
2026-03-14T20:52:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.