Skip to main content
Mallory
MalwareUsed by 4 actors

FlowCloud

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
TA410

Proofpoint researchers identified a new, additional malware family named FlowCloud that was also being delivered to U.S. utilities providers. FlowCloud malware, like LookBack, gives attackers complete control over a compromised system.

via proofpoint threat insight blogproofpoint.com
menuPass

Proofpoint researchers identified a new, additional malware family named FlowCloud that was also being delivered to U.S. utilities providers. FlowCloud malware, like LookBack, gives attackers complete control over a compromised system.

via proofpoint threat insight blogproofpoint.com
TA429

Proofpoint researchers identified a new, additional malware family named FlowCloud that was also being delivered to U.S. utilities providers. FlowCloud malware, like LookBack, gives attackers complete control over a compromised system.

via proofpoint threat insight blogproofpoint.com
TALONITE

"TALONITE uses two custom malware families that both feature multiple components known as LookBack and FlowCloud."

via dragos blogdragos.com
MITRE ATT&CK

Techniques & procedures

14 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence1

Proofpoint researchers observed phishing campaigns beginning on July 10, 2019 that targeted utility providers across the United States with portable executable (PE) attachments and used subject lines such as “PowerSafe energy educational courses (30-days trial)”... The content of the emails in the November 2019 campaigns impersonated the American Society of Civil Engineers and masqueraded as the legitimate domain asce[.]org.

T1566.001Spearphishing AttachmentEvidence1

These campaigns utilized malicious macro-laden documents in order to deliver modular malware to targeted utility providers across the U.S.... threat actors shifted from PE attachments to malicious macro laden Microsoft Word documents that closely resembled the same delivery and installation macros used in LookBack malware campaigns.

Execution

2 techniques
T1059.005Visual BasicEvidence1
TacticExecution

after an extended period of using PE attachments to deliver FlowCloud in campaigns, the threat actors behind FlowCloud switched to using Microsoft Word documents with malicious macros... FlowCloud uses this same method exactly including identical macro concatenation code.

T1204.002Malicious FileEvidence1
TacticExecution

The earlier LookBack versions of the macro included the payload in numerous privacy enhanced email (“.pem”) files that were dropped when the attachment file is executed by the user.

Persistence

2 techniques
T1112Modify RegistryEvidence1

EhStorAuthn.exe extracts the subsequent payload file components and installs them to the directory C:\Windows\Media\SystemPCAXD\ado\fc. This file also sets registry key values that store the keylogger drivers and the malware configuration as the value “KEY_LOCAL_MACHINE\SYSTEM\Setup\PrintResponsor\<2-4>”.

T1543.003Windows ServiceEvidence1

Responsor.dat unpacks several modules (rescure86.dat or rescure64.dat) to the registry %TEMP%\{0d47c9bc-7b04-4d81-9ad8-b2e00681de8e}" and installs the unpacked file as a service named “FSFilter Activity Monitor” or “FltMgr”.

T1055Process InjectionEvidence1

Dlcore.dll is a DLL crafted by the threat actors that functions as a shellcode injector pulling the shellcode from a file named rebare.dat... Several legitimate Microsoft Windows files were also used by the malware for thread injection.

T1543.003Windows ServiceEvidence1

Responsor.dat unpacks several modules (rescure86.dat or rescure64.dat) to the registry %TEMP%\{0d47c9bc-7b04-4d81-9ad8-b2e00681de8e}" and installs the unpacked file as a service named “FSFilter Activity Monitor” or “FltMgr”.

Stealth

3 techniques
T1036MasqueradingEvidence1
TacticStealth

The senders of the emails that delivered FlowCloud malware utilized threat actor-controlled domains for delivery which impersonated energy sector training services... The content of the emails in the November 2019 campaigns impersonated the American Society of Civil Engineers and masqueraded as the legitimate domain asce[.]org.

T1055Process InjectionEvidence1

Dlcore.dll is a DLL crafted by the threat actors that functions as a shellcode injector pulling the shellcode from a file named rebare.dat... Several legitimate Microsoft Windows files were also used by the malware for thread injection.

T1218.010Regsvr32Evidence1
TacticStealth

This file is next saved as a portable executable file named “gup.exe” and executed using a version of the certutil.exe tool named “Temptcm.tmp”.

T1112Modify RegistryEvidence1

EhStorAuthn.exe extracts the subsequent payload file components and installs them to the directory C:\Windows\Media\SystemPCAXD\ado\fc. This file also sets registry key values that store the keylogger drivers and the malware configuration as the value “KEY_LOCAL_MACHINE\SYSTEM\Setup\PrintResponsor\<2-4>”.

T1056.001KeyloggingEvidence1

The malware stores its configuration in the registry alongside drivers utilized by the malware’s keylogger components.

Collection

1 technique
T1056.001KeyloggingEvidence1

The malware stores its configuration in the registry alongside drivers utilized by the malware’s keylogger components.

T1071Application Layer ProtocolEvidence1

FlowCloud malware handles configuration updates, file exfiltration, and commands as independent threads utilizing a custom binary C2 protocol.

T1105Ingress Tool TransferEvidence1

The FlowCloud version of the macro utilized a previously unobserved macro section to download the payload from a DropBox URL... if it was unable to retrieve the payload from that resource, a catch statement... attempted to retrieve a malware resource from the URL http://ffca.caibi379[.]com/rwjh/qtinfo.txt

T1219Remote Access ToolsEvidence1

FlowCloud malware, like LookBack, gives attackers complete control over a compromised system. Its remote access trojan (RAT) functionality includes the ability to access installed applications, the keyboard, mouse, screen, files, services, and processes with the ability to exfiltrate information via command and control.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

FlowCloud malware handles configuration updates, file exfiltration, and commands as independent threads utilizing a custom binary C2 protocol. The sample we analyzed utilized port 55555 for file exfiltration and port 55556 for all other data.

INDICATORS OF COMPROMISE

IOCs tracked for this family

32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
15 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
15 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
2 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app4 years ago
domain●●●●●●●●●●●●View more in app6 years ago
domain●●●●●●●●●●●●View more in app6 years ago
hash.sha256●●●●●●●●●●●●View more in app6 years ago
hash.sha256●●●●●●●●●●●●View more in app6 years ago
hash.sha256●●●●●●●●●●●●View more in app6 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching32

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution4

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping14

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.