Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
2026-03-12T20:52:20Z•b761bbdbe01e48aa7d4d7d681ff47f7050eda61f1d982ec11b273e47654934cf
AiTM phishingCoral SleetEV certificate theftFlexibleFerretIOCsJasper SleetLLM data exfiltrationOtterCookieRMM backdoorsSEO poisoningStorm-2561Tycoon2FAcredential theftdeveloper-targeted attacksfake VPNmalicious browser extensionsmitigationsprompt abuseprompt injectionsigned malwarethreat hunting
What happened
Microsoft Security Blog highlights multiple active campaigns and trends: Storm-2561 (active since 2025) uses SEO poisoning to push fake VPN clients that install signed trojans and harvest VPN credentials while impersonating trusted vendors and abusing legitimate services; Microsoft published TTPs, IOCs, and mitigations. Related reporting covers large-scale AiTM phishing (Tycoon2FA) and disruptions, malicious AI browser extensions harvesting LLM chat histories at scale, prompt-injection risks in AI tools, developer-targeted malware distribution via fake job interviews (OtterCookie, FlexibleFer
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- b761bbdbe01e48aa7d4d7d681ff47f7050eda61f1d982ec11b273e47654934cf
- Enrichment time
- 2026-03-12T20:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.