Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft

2026-03-16T02:52:16Z74ee943724ad2318c23028781016b4438d7fea5f019bd3628e4f0ef110ce2058
AiTMEV certificate abuseLLM data exfiltrationRMM backdoorsSEO poisoningStorm-2561Tycoon2FAcredential theftfake VPNmalicious browser extensionsphishing-as-a-serviceprompt injectionsigned malwaresupply-chain impersonation

What happened

Microsoft reports that the Storm-2561 cluster (active since 2025) uses SEO poisoning to push fake VPN installers which include signed trojans that harvest VPN credentials by mimicking trusted vendors and abusing legitimate services. The feed also highlights related threats and trends: AiTM/phishing-as-a-service scale enabled by Tycoon2FA, signed malware using stolen EV certificates to deploy RMM backdoors, recruitment-themed delivery of backdoors (OtterCookie, FlexibleFerret), malicious browser extensions harvesting LLM chat histories, and risks from prompt-injection—each entry includes TTPs,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
74ee943724ad2318c23028781016b4438d7fea5f019bd3628e4f0ef110ce2058
Enrichment time
2026-03-16T02:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.