Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
2026-03-16T02:52:16Z•74ee943724ad2318c23028781016b4438d7fea5f019bd3628e4f0ef110ce2058
AiTMEV certificate abuseLLM data exfiltrationRMM backdoorsSEO poisoningStorm-2561Tycoon2FAcredential theftfake VPNmalicious browser extensionsphishing-as-a-serviceprompt injectionsigned malwaresupply-chain impersonation
What happened
Microsoft reports that the Storm-2561 cluster (active since 2025) uses SEO poisoning to push fake VPN installers which include signed trojans that harvest VPN credentials by mimicking trusted vendors and abusing legitimate services. The feed also highlights related threats and trends: AiTM/phishing-as-a-service scale enabled by Tycoon2FA, signed malware using stolen EV certificates to deploy RMM backdoors, recruitment-themed delivery of backdoors (OtterCookie, FlexibleFerret), malicious browser extensions harvesting LLM chat histories, and risks from prompt-injection—each entry includes TTPs,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 74ee943724ad2318c23028781016b4438d7fea5f019bd3628e4f0ef110ce2058
- Enrichment time
- 2026-03-16T02:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.