Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
2026-03-14T08:52:23Z•6dbb5dba9964a449091c25257bf121db8a57845d346c0f02f45bd709b5f5c1aa
ai-as-tradecraftai-assistant-extensionsaitm-phishingcontagious-interviewcredential-theftemail-securityfake-vpnflexibleferretiocsllm-data-exfiltrationmitigationottercookieprompt-injectionrmm-backdoorsseo-poisoningsigned-malwarestolen-ev-certificatestorm-2561threat-inteltycoon2fa
What happened
Microsoft Security Blog posts (Mar 3–12, 2026) describing multiple active campaigns and defensive guidance: Storm-2561 uses SEO poisoning to distribute fake, signed VPN clients that install trojans and steal VPN credentials; Contagious Interview lures developers with fake job interviews to deliver backdoors (OtterCookie, FlexibleFerret) that steal API tokens, cloud credentials, wallets, and source code; malicious AI browser extensions harvested LLM chat histories at scale across many tenants; Tycoon2FA AiTM phishing-as-a-service operated at large scale and was disrupted; signed malware using a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 6dbb5dba9964a449091c25257bf121db8a57845d346c0f02f45bd709b5f5c1aa
- Enrichment time
- 2026-03-14T08:52:23Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.