Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Proofpoint researchers identified a new, additional malware family named FlowCloud that was also being delivered to U.S. utilities providers. FlowCloud malware, like LookBack, gives attackers complete control over a compromised system.
Proofpoint researchers identified a new, additional malware family named FlowCloud that was also being delivered to U.S. utilities providers. FlowCloud malware, like LookBack, gives attackers complete control over a compromised system.
Proofpoint researchers identified a new, additional malware family named FlowCloud that was also being delivered to U.S. utilities providers. FlowCloud malware, like LookBack, gives attackers complete control over a compromised system.
"TALONITE uses two custom malware families that both feature multiple components known as LookBack and FlowCloud."
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Proofpoint researchers observed phishing campaigns beginning on July 10, 2019 that targeted utility providers across the United States with portable executable (PE) attachments and used subject lines such as “PowerSafe energy educational courses (30-days trial)”... The content of the emails in the November 2019 campaigns impersonated the American Society of Civil Engineers and masqueraded as the legitimate domain asce[.]org.
These campaigns utilized malicious macro-laden documents in order to deliver modular malware to targeted utility providers across the U.S.... threat actors shifted from PE attachments to malicious macro laden Microsoft Word documents that closely resembled the same delivery and installation macros used in LookBack malware campaigns.
after an extended period of using PE attachments to deliver FlowCloud in campaigns, the threat actors behind FlowCloud switched to using Microsoft Word documents with malicious macros... FlowCloud uses this same method exactly including identical macro concatenation code.
EhStorAuthn.exe extracts the subsequent payload file components and installs them to the directory C:\Windows\Media\SystemPCAXD\ado\fc. This file also sets registry key values that store the keylogger drivers and the malware configuration as the value “KEY_LOCAL_MACHINE\SYSTEM\Setup\PrintResponsor\<2-4>”.
The senders of the emails that delivered FlowCloud malware utilized threat actor-controlled domains for delivery which impersonated energy sector training services... The content of the emails in the November 2019 campaigns impersonated the American Society of Civil Engineers and masqueraded as the legitimate domain asce[.]org.
EhStorAuthn.exe extracts the subsequent payload file components and installs them to the directory C:\Windows\Media\SystemPCAXD\ado\fc. This file also sets registry key values that store the keylogger drivers and the malware configuration as the value “KEY_LOCAL_MACHINE\SYSTEM\Setup\PrintResponsor\<2-4>”.
FlowCloud malware handles configuration updates, file exfiltration, and commands as independent threads utilizing a custom binary C2 protocol.
The FlowCloud version of the macro utilized a previously unobserved macro section to download the payload from a DropBox URL... if it was unable to retrieve the payload from that resource, a catch statement... attempted to retrieve a malware resource from the URL http://ffca.caibi379[.]com/rwjh/qtinfo.txt
FlowCloud malware, like LookBack, gives attackers complete control over a compromised system. Its remote access trojan (RAT) functionality includes the ability to access installed applications, the keyboard, mouse, screen, files, services, and processes with the ability to exfiltrate information via command and control.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
FlowCloud is a multi-stage C++ remote access trojan with modular components, keylogging capability, file and process access, screen/keyboard/mouse monitoring, service management, and data exfiltration over a custom binary C2 protocol. It uses legitimate and imitation QQ components during execution and stores encrypted configuration data in the registry.
Custom multi-component malware family used by the TALONITE threat group in spearphishing-driven initial access compromises, supporting intrusion and follow-on operations in the electric sector.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.