FlowerStorm is a phishing-as-a-service operation active since at least June 2024 that specializes in adversary-in-the-middle credential and multifactor authentication token theft, primarily against Microsoft 365 users. It is closely associated with the broader DadSec lineage of phishing kits and shares notable technical and operational similarities with Rockstar2FA and Tycoon, including Telegram-backed operator workflows, comparable portal structure, similar backend communications, Cloudflare Turnstile usage, and overlapping page construction patterns. Available reporting supports common ancestry with Rockstar2FA, but does not establish with high confidence that both services are run by the same operators. The platform provides phishing portals used to capture credentials and session material from targeted users, enabling follow-on access to victim accounts. In observed cases, infrastructure used for credential harvesting was also used shortly afterward to authenticate to victim accounts, indicating direct operational use of stolen authentication data. FlowerStorm has been observed targeting organizations predominantly in the United States, Canada, the United Kingdom, Australia, and Italy, with the service sector the most heavily targeted. FlowerStorm’s known behavior supports classification as a financially motivated cybercriminal service rather than a state-sponsored intrusion set. Its capabilities center on initial access through phishing, credential theft, session hijacking via MFA token capture, and exfiltration of stolen authentication material to backend infrastructure. It forms part of the 2024 ecosystem of commercialized MFA-phishing platforms that lowered the barrier to entry for account compromise operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing-as-a-service platform active since at least June 2024 that uses phishing portals and backend PHP infrastructure to harvest credentials and MFA approvals, with activity increasing after Rockstar2FA infrastructure disruption.
FlowerStorm is a phishing group or platform using updated Dadsec-based adversary-in-the-middle MFA phishing kits, leveraging Telegram for C2, and targeting organizations for credential and token theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.