Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft
2026-03-13T14:52:20Z•fa7b55c06e2243095a74c349c0c2427681d52aa8d5663dd20ec86b71059c1925
AiTM phishingFlexibleFerretIOCsLLM data exfiltrationMicrosoft DefenderOtterCookieRMM backdoorSEO poisoningStorm-2561Tycoon2FAcredential theftdeveloper-targetingemail security benchmarkfake VPNmalicious browser extensionsmitigation guidancephishing-as-a-serviceprompt injectionsigned malwarestolen EV certificate
What happened
This Microsoft Security Blog feed highlights multiple active, high-impact campaigns and trends: Storm-2561 uses SEO poisoning to distribute fake VPN clients that install signed trojans and steal VPN credentials while mimicking trusted brands and abusing legitimate services; developer-targeting “Contagious Interview” lures deliver backdoors (OtterCookie, FlexibleFerret) to harvest API tokens, cloud credentials, crypto wallets, and source code; malicious AI browser extensions exfiltrate LLM chat histories and browsing data at scale (hundreds of thousands of installs spanning many enterprise ten‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- fa7b55c06e2243095a74c349c0c2427681d52aa8d5663dd20ec86b71059c1925
- Enrichment time
- 2026-03-13T14:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.