Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
2026-03-16T14:52:22Z•e43e59d25caa92766d6d93b1e3a4f3ddaf799a8b1db69e6e2ab1808f0d2d336b
AiTM phishingCoral SleetEV certificate abuseFlexibleFerretJasper SleetLLM data exfiltrationOtterCookieRMM backdoorSEO poisoningStorm-2561Tycoon2FAcredential theftdeveloper-targeted luresemail security benchmarkingfake VPNmalicious browser extensionsmitigationsphishing-as-a-serviceprompt injectionsigned malware
What happened
Microsoft Security Blog posts summarize multiple active, high-impact campaigns and trends: Storm-2561 uses SEO poisoning to distribute fake VPN clients (signed trojans) that steal VPN credentials and impersonate trusted brands; Tycoon2FA is a large-scale AiTM phishing-as-a-service affecting hundreds of thousands of organizations; signed malware leveraging stolen EV certificates has been used to deploy legitimate RMM tools for persistent access. Other coverage highlights developer-targeted lures (Contagious Interview delivering OtterCookie and FlexibleFerret to harvest API tokens, cloud creds,‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- e43e59d25caa92766d6d93b1e3a4f3ddaf799a8b1db69e6e2ab1808f0d2d336b
- Enrichment time
- 2026-03-16T14:52:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.