Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft

2026-03-13T14:52:20Zfa7b55c06e2243095a74c349c0c2427681d52aa8d5663dd20ec86b71059c1925
AiTM phishingFlexibleFerretIOCsLLM data exfiltrationMicrosoft DefenderOtterCookieRMM backdoorSEO poisoningStorm-2561Tycoon2FAcredential theftdeveloper-targetingemail security benchmarkfake VPNmalicious browser extensionsmitigation guidancephishing-as-a-serviceprompt injectionsigned malwarestolen EV certificate

What happened

This Microsoft Security Blog feed highlights multiple active, high-impact campaigns and trends: Storm-2561 uses SEO poisoning to distribute fake VPN clients that install signed trojans and steal VPN credentials while mimicking trusted brands and abusing legitimate services; developer-targeting “Contagious Interview” lures deliver backdoors (OtterCookie, FlexibleFerret) to harvest API tokens, cloud credentials, crypto wallets, and source code; malicious AI browser extensions exfiltrate LLM chat histories and browsing data at scale (hundreds of thousands of installs spanning many enterprise ten‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
fa7b55c06e2243095a74c349c0c2427681d52aa8d5663dd20ec86b71059c1925
Enrichment time
2026-03-13T14:52:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft · Baitaphish