FLASHFLOOD is a Windows malware family associated with file collection and staging activity focused on documents and other files of interest from both local systems and removable media. It performs file and directory discovery, searches for files matching a default or operator-customized extension set, and copies selected data from local drives and attached removable media into a local staging area. Collected data is archived via a custom method before exfiltration preparation. FLASHFLOOD is also documented as establishing persistence through Windows Registry Run keys or the Startup folder, allowing execution after logon or reboot. Its tradecraft aligns with espionage-oriented collection operations, particularly where removable media is used as an additional source of victim data. FLASHFLOOD has been cataloged in ATT&CK as malware S0036.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
AppleSeed can find and collect data from removable media devices. APT28 backdoor may collect the entire contents of an inserted USB device. Aria-body has the ability to collect data from USB devices. BADNEWS copies files with certain extensions from USB devices to a predefined directory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that establishes persistence through a Registry Run key entry.
Malware that searches local systems for interesting files and collects additional user data such as Windows Address Book contents.
Backdoor malware that persists via a Registry Run key.
Data collection and staging malware that archives collected data, persists via registry run keys, gathers data from local systems and removable media, and stages it locally.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.