Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

FlowerStorm

7
Global rank
4 infographic chevron month
Month rank
4 infographic chevron week
Week rank
0
IOCs

FlowerStorm is a phishing-as-a-service (PhaaS) platform used by cybercriminals to steal Microsoft 365 credentials and bypass multi-factor authentication (MFA) protections through adversary-in-the-middle (AiTM) attacks. Emerging after the disruption of Rockstar2FA in late 2024, FlowerStorm rapidly gained popularity among attackers targeting enterprises across North America and Europe.

Phishingkit
Type
Unknown
Origin
1 June, 2024
First seen
9 September, 2026
Last seen

How to analyze FlowerStorm with ANY.RUN

Type
Unknown
Origin
1 June, 2024
First seen
9 September, 2026
Last seen

IOCs

IP addresses
52.123.243.92
52.168.112.66
204.79.197.203
48.209.6.48
48.209.138.168
150.171.28.11
23.52.181.141
135.232.92.97
188.114.97.3
40.126.31.67
52.123.224.72
48.209.138.189
104.18.18.203
35.190.80.1
135.233.95.144
142.250.154.95
13.107.246.45
48.192.1.64
151.101.65.155
52.102.113.16
Hashes
239721c2965f409d245952f9dce02135bb9f8e7e9cfb245c1e1b8e8a9c8b751c
db39694c444ea393569aafb2cd8ec865006f3df9ecbcb7996e7b219b30ec366d
a796b38365910aa3443c68fa88e9f1e91afc0ac9d9478dd631b026555505d9ab
cf5916e86bb18875db4e12ee5e799cce7b23bc1cd1ad721fb65d3879de629bec
5e3fb19f1c3adc1bf6b753841c98653548f0e00e7f9be8b857927d5a66ff73e1
82f1f7f245389a467e4c5615f443f7c8d5c25244f3ff20bb42f7480a4bcfecf6
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
3a657eddec2905ce29950e37a3cc78c6839afc858fe26a89490a1502be032d13
b875dc4dff70cd329ac5a2bc34de29b202325f73e4924ca00d2c1854ab5da177
55ce3b0ce5bc71339308107982cd7671f96014256ded0be36dc8062e64c847f1
cbb3706e65b35a43bdcfebd23b5479dc0542ca7e23197869b683d12b524472fe
f7c8d211703eba3aeec88096b0ab128b4372251c9069b932fa7889598c8c2236
b02b5df3ecd59d6cd90c60878683477532cbfc24660028657f290bdc7bc774b5
14bf8af0ec00ec4d1b1c48ed250d95f1917a05b4480866a0f0d3e6575f2fb0ba
10a1528b1d717b40889dfe6e9a16cb33fad7e760e037149ddbe4943f602b9118
d2bb091268ade68ad8121d2184d0fbce128070156304bd4de312e6fbd267409c
a8063ec414541f62ea19faa20c3b0a8ee8690ac18cf5ab8854c9e459df93c003
b78f7d132ccb5d02a28bdb3343d35dfd1332784b67ffbd5f437bac0ca53d644f
Domains
slscr.update.microsoft.com
code.jquery.com
c.pki.goog
api.edgeoffer.microsoft.com
settings-win.data.microsoft.com
cdn.jsdelivr.net
logincdn.msftauth.net
ci3.googleusercontent.com
edge.microsoft.com
self.events.data.microsoft.com
www.microsoft.com
omex.cdn.office.net
aadcdn.msauth.net
pub-52ce26e5ae424f138456fe4245bd147c.r2.dev
go.microsoft.com
oneocsp.microsoft.com
rnke.servicereliabilityexperts.de
google.com
ocsp.digicert.com
activation-v2.sls.microsoft.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://officeclient.microsoft.com/config16/?lcid=1033&syslcid=1033&uilcid=1033&build=16.0.16026&crev=3
https://ecs.office.com/config/v2/office/outlook/16.0.16026.20146/production/cc?&clientid=%7bd61ab268-c26a-439d-bb15-2a0dedfca6a3%7d&application=outlook&platform=win32&version=16.0.16026.20146&msoversion=16.0.16026.20002&sdx=fa000000002.2.0.1907.31003&sdx=fa000000005.1.0.1909.30011&sdx=fa000000006.1.0.1909.13002&sdx=fa000000008.1.0.1908.16006&sdx=fa000000009.1.0.1908.6002&sdx=fa000000016.1.0.1810.13001&sdx=fa000000029.1.0.1906.25001&sdx=fa000000033.1.0.1908.24001&sdx=wa104381125.1.0.1810.9001&processname=outlook.exe&audience=production&build=ship&architecture=x64&language=en-us&subscriptionlicense=false&perpetuallicense=2019&licensecategory=6&licensesku=professional2019retail&osversion=10.0&osbuild=19045&channel=cc&installtype=c2r&sessionid=%7b3f168715-4a95-415b-afe4-5f2ea33313b2%7d&labmachine=false
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceasmayxgarewr3pgr9svwmg%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbr0tbevyklx7a9ylold9hqmcwdxfgqu3pggslehmvkx8utfb6ncihnaqhycezmaaaale%2bvmfuqbvyaaaaaaaas%3d
https://roaming.svc.cloud.microsoft/rs/roamingsoapservice.svc
https://messaging.lifecycle.office.com/getcustommessage16?app=6&ui=en-us&src=bizbar&messagetype=bizbar&hwid=04111-083-043729&ver=16.0.16026&lc=en-us&platform=10%3a0%3a19045%3a2%3a0%3a0%3a256%3a1%3a&productid=%7b1717c1e0-47d3-4899-a6d3-1022db7415e0%7d%3a00411-10830-43729-aa720%3aoffice%2019%2c%20office19professional2019r_retail%20edition&clientsessionid=%7b3f168715-4a95-415b-afe4-5f2ea33313b2%7d&datapropertybag=%7b%22audience%22%3a%22production%22%2c%22audiencegroup%22%3a%22production%22%2c%22audiencechannel%22%3a%22cc%22%2c%22flight%22%3a%22ofsh6c2b1tla1a31%2cofcrui4yvdulbf31%2cofhpex3jznepoo31%22%7d
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://editor.svc.cloud.microsoft/nleditor/cloudsuggest/v1
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://self.events.data.microsoft.com/onecollector/1.0/
https://ci3.googleusercontent.com/meips/adkq_nbhojtum05ps-tjbl3wyfjhxknpn8cmq7joonnjzjvjb6kfmvqesbb8zna6ntvuqxnxalbdq3im6mh4_0g6kraquqgu2rofiwga3bidc9xy4auqkjco=s0-d-e1-ft
https://ci3.googleusercontent.com/meips/adkq_nyk4-ri2wmdafd2or9sbjbv32jadtqdregd5af_5nkf0ktic1-umuvjlkrguodub-sjla6u7u0qnqhcupyn4x25hzs1gryjsh5rd1rftnhqgoc=s0-d-e1-ft
Last Seen at

Recent blog posts

post image
HVNC Backdoor Targets LATAM Organizations wit...
watchers 1968
comments 0
post image
Release Notes: Faster TI Investigations, Fres...
watchers 6932
comments 0
post image
Triage & Response Bottlenecks Eating into...
watchers 5634
comments 0

FlowerStorm Rising: From Rockstar2FA Successor to Enterprise Account Takeover Machine

Key Takeaways

  1. FlowerStorm is a phishing-as-a-service platform focused on Microsoft 365 credential theft.
  2. The platform uses adversary-in-the-middle phishing to bypass MFA protections.
  3. Professional services, finance, manufacturing, and legal sectors are among the most targeted industries.
  4. FlowerStorm emerged after the disruption of Rockstar2FA and inherited many similar techniques.
  5. Stolen Microsoft 365 sessions can lead to BEC fraud, lateral movement, and large-scale compromise.
  6. Rapidly rotating phishing infrastructure makes traditional blocking approaches less effective. Detection relies on behavioral anomalies rather than just signatures.
  7. ANY.RUN's Threat Intelligence Lookup lets analysts instantly query any suspicious indicator against a vast, sandbox-validated database to confirm FlowerStorm association and see the full attack context.

destinationIP:"172.67.215.79".

FlowerStorm IP in sandbox analyses FlowerStorm IP in sandbox analyses

Threat Intelligence Feeds automatically streams verified FlowerStorm IOCs (malicious IPs, domains, URLs) directly into SIEM, IDS/IPS, and EDR systems in STIX/TAXII format, enabling automated blocking of new phishing infrastructure before it reaches users.

What is FlowerStorm Malware?

FlowerStorm is a commercially operated PhaaS platform that equips threat actors with everything needed to run professional-grade phishing campaigns. Unlike traditional phishing kits that simply collect entered passwords, FlowerStorm employs real-time AiTM proxy infrastructure. When a victim visits a fake Microsoft 365 login page and authenticates, FlowerStorm's backend relays those credentials to the real Microsoft service, intercepts the resulting authenticated session cookie, and delivers it to the attacker. The attacker can then replay that cookie and gain full access to the victim's account without ever knowing their password or needing to satisfy an MFA prompt.

The platform shares extensive structural and operational similarities with Rockstar2FA, a preceding PhaaS operation, with researchers suggesting at minimum a common ancestry between the two.

FlowerStorm's phishing portals are designed to closely mimic legitimate Microsoft 365 login pages, complete with Cloudflare Turnstile CAPTCHA challenges to block automated security scanners.

Credential data and JWT session tokens are exfiltrated to attacker-controlled backend servers using a standardized PHP file (next.php), which communicates via .ru, .moscow, and .com domains, as well as Cloudflare Pages infrastructure under .dev domains. The platform supports email validation, MFA relay, and session tracking, making it a complete identity theft engine.

ANY.RUN’s Interactive Sandbox allows to safely detonate FlowerStorm samples and analyse full attack chain, connections, and processes:

View sandbox session

FlowerStorm analysis in Interactive Sandbox FlowerStorm detonated in Interactive Sandbox

The platform uses plant-themed HTML titles (e.g., "Sprout," "Blossom," "Flower," "Leaf") for its phishing pages. It operates as a subscription service, often managed via Telegram bots, allowing even less-skilled attackers to deploy convincing fake Microsoft login portals.

How FlowerStorm Threatens Businesses and Organizations

FlowerStorm poses severe risks by enabling full account takeover of Microsoft 365 and associated enterprise resources. Once attackers obtain session tokens:

  • They gain persistent access without passwords or ongoing MFA prompts.
  • Attackers can perform lateral movement, data exfiltration, privilege escalation (e.g., password resets, role changes), and deployment of additional malware or ransomware.
  • Compromised accounts serve as entry points for business email compromise (BEC), supply chain attacks, or intellectual property theft.
  • Financial losses, regulatory fines (e.g., GDPR), reputational damage, and operational disruptions often follow.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Who Is Most at Risk?

FlowerStorm and similar AiTM PhaaS kits disproportionately target organizations heavily reliant on Microsoft 365 for email, collaboration, and identity management.

Especially vulnerable sectors include:

  • Services (e.g., engineering, consulting, legal, real estate). High volume of email-based workflows.
  • Finance and Insurance. High-value data; targeted with spearphishing (e.g., QR-code PDFs).
  • Manufacturing and Retail. Supply chain and operational dependencies.
  • Healthcare and IT/Telecom. Critical data and infrastructure (e.g., recent German campaigns).

How FlowerStorm Gets In the System and Spreads?

FlowerStorm's attack chain begins at the inbox and, if successful, expands through the victim's network and contacts. The initial delivery mechanism relies primarily on crafted phishing emails, with the platform providing affiliates with the infrastructure to customize and deploy campaigns at scale.

Initial Delivery:

Victims receive a phishing email designed to create urgency or simulate a legitimate notification. FlowerStorm operators and their affiliates have used a variety of lure themes, including Microsoft security alerts, shared document notifications, HR communications (such as new employee announcements), and invoice or payment requests. The email contains a link that begins redirecting the victim through a chain of intermediary pages often hosted on legitimate services like Cloudflare Pages to obscure the final malicious destination from email security scanners.

Evasion of Automated Detection:

Multiple stages in the redirect chain use legitimate infrastructure (cloud CDNs, trusted domains) to make individual URLs appear benign. Cloudflare Turnstile CAPTCHA challenges are embedded in the phishing pages both to appear legitimate and to prevent security bots and web crawlers from analyzing the final landing page. The platform also employs JavaScript-based conditional page loading, so the malicious content is only served if the visitor appears to be a genuine human user.

Credential and Session Theft:

Once the victim reaches the fake Microsoft 365 login page and enters their credentials, FlowerStorm's AiTM proxy relays those credentials to the real Microsoft authentication service in real time. The victim successfully completes their MFA challenge (SMS code, authenticator app, push notification), and the resulting authenticated session cookie is intercepted by FlowerStorm's backend server via the next.php communication file. The victim is then redirected to a legitimate Microsoft page, often experiencing nothing unusual.

Post-Compromise Spread:

With a valid session cookie, the attacker logs into the victim's Microsoft 365 account. From this position, the attack can spread in several directions: internal phishing emails sent from the trusted compromised account, access to connected applications and data stores, password resets and privilege escalation to deepen control, and creation of persistent access mechanisms such as new OAuth app authorizations or hidden inbox rules.

How FlowerStorm Malware Functions

At its core, FlowerStorm is a reverse-proxy phishing platform.

AiTM Proxy Architecture:

The attacker's server acts as a real-time man-in-the-middle between the victim's browser and the legitimate Microsoft authentication service. When the victim submits credentials, the proxy forwards them to Microsoft, receives a valid response (including an MFA challenge), and relays that challenge back to the victim. When the victim completes the MFA step, Microsoft issues an authenticated session cookie, which the proxy intercepts before passing the legitimate session back to the user.

Backend Communication (next.php):

FlowerStorm standardized its backend communication around a PHP file called next.php. This file handles credential transmission (email, password), JWT token exchange for session tracking, MFA relay logic, and success/failure signaling.

Anti-Bot and Evasion Mechanisms:

  • Cloudflare Turnstile CAPTCHA (both legitimate integrations and customized implementations)
  • Random junk text in HTML comments to frustrate pattern-matching
  • Multi-stage redirect chains through legitimate CDNs and hosting services
  • JavaScript-driven conditional rendering to serve malicious content only to verified human visitors
  • Domain rotation and use of Cloudflare services for hosting resilience

Credential Harvesting Fields:

The phishing portal captures standard Microsoft login fields (email, password) along with MFA tokens and session identifiers. The backend supports email-address validation (to confirm a target is a genuine corporate user before serving the full phishing flow) and dynamic MFA challenge relay.

How Businesses Can Proactively Protect Against FlowerStorm

Modern phishing threats move too quickly for static indicators alone. Security teams need continuous visibility into:

  • Emerging phishing domains,
  • Infrastructure overlaps,
  • IOC relationships,
  • Active attack patterns,
  • Malware delivery chains.

This is where Threat Intelligence becomes operational rather than theoretical.

With Threat Intelligence Lookup, analysts can:

  • Search FlowerStorm-related IOCs
  • Correlate domains, IPs, and phishing artifacts
  • Identify infrastructure reuse
  • Investigate suspicious Microsoft 365 phishing activity
  • Hunt for campaign overlaps

This helps SOC teams pivot from isolated alerts to full attack-chain visibility. Start the research with the threat name:

threatName:"flowerstorm".

FlowerStorm summary in TI Lookup FlowerStorm summary in TI Lookup

Threat Intelligence Feeds help organizations to:

  • Continuously ingest fresh FlowerStorm indicators
  • Automate detections,
  • Enrich SIEM and SOAR workflows,
  • Block malicious domains proactively,
  • Improve phishing detection coverage.

The biggest advantage is speed. FlowerStorm infrastructure changes rapidly, so automated IOC enrichment becomes critical.

Additional Measures:

Organizations should also:

  • Deploy phishing-resistant MFA such as FIDO2
  • Monitor impossible travel and session anomalies
  • Implement conditional access policies
  • Conduct continuous phishing awareness training
  • Use sandbox analysis for suspicious files and links
  • Monitor for MFA fatigue and session hijacking indicators
  • Harden Microsoft 365 identity protections

A layered defense strategy is essential because no single control can stop AiTM phishing alone.

FlowerStorm Sandbox Analysis

Using ANY.RUN’s Interactive Sandbox, analysts can detonate a suspicious file or a link, get it detected as a FlowerStorm attack sample, and observe the behavior, TTPs, and kill chain along with gathering additional IOCs.

View FlowerStorm analysis session

FlowerStorm summary in TI Lookup FlowerStorm summary in TI Lookup

The attack begins with an email disguised as a work document, a protected attachment, or a notification requiring review. Instead of being taken directly to a phishing page, the user is often first directed to an intermediate screen with a button to access the document or confirm opening the file.

File opening request File opening request

An important detail for SOC teams: The intermediate page can be hosted on legitimate infrastructure, such as platforms like Google Sites. This increases the victim’s trust and simultaneously complicates early detection, because the first stage of the attack chain passes through a well-known and generally legitimate service rather than an obviously malicious resource.

Page hosted on Google Sites Page hosted on Google Sites

Next, the victim is redirected to a fake login page styled to look like Microsoft 365 or another cloud service. Visually, it replicates the normal authentication process: a familiar interface, standard login steps, and typical credential verification logic.

Fake Microsoft sign-in form Fake Microsoft sign-in form

The key feature of FlowerStorm is that it does not operate as a primitive login and password stealer. Its goal is to guide the user through the entire authentication process, including the second factor, in order to obtain not only credentials but also artifacts of an active session. This allows attackers to use already authenticated access and bypass MFA not by “breaking” it, but by essentially hijacking the result of a successful login.

CAPTCHA or other anti-bot checks are often used in the chain. For attackers, this serves two purposes at once: such elements make the scenario more believable to the user and simultaneously hinder sandboxes, URL scanners, and some automated analysis tools from seeing the full attack chain. ANY.RUN’s Sandbox can interact with such elements emulating user behavior:

CAPTCHA bypassed by Sandbox CAPTCHA bypassed by Sandbox

After successfully completing all stages, attackers gain access to the cloud session and can act on behalf of the user without triggering immediate additional MFA prompts. Therefore, the real danger of FlowerStorm lies not only in stealing the password, but in the subsequent session hijacking, which can outwardly appear as normal user activity.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

FlowerStorm represents the commoditization of advanced AiTM phishing, lowering the barrier for attackers while raising the stakes for organizations. Its rapid evolution and focus on Microsoft 365 highlight the need for proactive, intelligence-driven defenses beyond traditional MFA. By combining human vigilance with advanced tools like ANY.RUN's TI solutions and robust identity security, businesses can significantly reduce exposure.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Arechclient2 screenshot
Arechclient2
arechclient2
The Arechclient2 malware is a sophisticated .NET-based Remote Access Trojan (RAT) that collects sensitive information, such as browser credentials, from infected computers. It employs various stealth techniques, including Base64 encoding to obscure its code and the ability to pause activities to evade automated security tools. The malware also can adjust Windows Defender settings and uses code injection to manipulate legitimate processes.
Read More
SVCStealer screenshot
SVCStealer
svcstealer
SVCStealer is an information-stealing malware targeting sensitive user data through spear-phishing email attachments. It systematically extracts credentials, financial data, and system information from various applications, including browsers and messaging platforms.
Read More
GREENBLOOD screenshot
GREENBLOOD
greenblood
GREENBLOOD is a Go-based ransomware that uses concurrent ChaCha8 encryption to lock entire Windows environments in under a minute while systematically destroying backups, disabling defenses, and threatening double extortion through a Tor-based data leak site.
Read More
Agent Tesla screenshot
Agent Tesla
agenttesla trojan rat stealer
Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold.
Read More
Ransomware screenshot
Ransomware
ransomware
Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.
Read More
DoubleTrouble screenshot
DoubleTrouble
doubletrouble
DoubleTrouble is a new-generation Android malware designed to quietly infiltrate mobile devices, harvest sensitive data, hijack financial operations, and maintain long-term persistence. Unlike commodity Android trojans, it blends advanced evasion, dual-stage infection, and dynamic payload updates, making it a rising mobile threat for both consumers and organizations.
Read More