Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft

2026-03-12T20:52:20Zb761bbdbe01e48aa7d4d7d681ff47f7050eda61f1d982ec11b273e47654934cf
AiTM phishingCoral SleetEV certificate theftFlexibleFerretIOCsJasper SleetLLM data exfiltrationOtterCookieRMM backdoorsSEO poisoningStorm-2561Tycoon2FAcredential theftdeveloper-targeted attacksfake VPNmalicious browser extensionsmitigationsprompt abuseprompt injectionsigned malwarethreat hunting

What happened

Microsoft Security Blog highlights multiple active campaigns and trends: Storm-2561 (active since 2025) uses SEO poisoning to push fake VPN clients that install signed trojans and harvest VPN credentials while impersonating trusted vendors and abusing legitimate services; Microsoft published TTPs, IOCs, and mitigations. Related reporting covers large-scale AiTM phishing (Tycoon2FA) and disruptions, malicious AI browser extensions harvesting LLM chat histories at scale, prompt-injection risks in AI tools, developer-targeted malware distribution via fake job interviews (OtterCookie, FlexibleFer­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
b761bbdbe01e48aa7d4d7d681ff47f7050eda61f1d982ec11b273e47654934cf
Enrichment time
2026-03-12T20:52:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft · Baitaphish