Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The vulnerability was actively exploited in the wild, with threat actors deploying the Flodric botnet through compromised Langflow instances, as documented by Trend Micro’s research.
Additionally, threat actors deployed the Flodric botnet through compromised Langflow instances.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
An allow_origins='*' with allow_credentials=True CORS configuration combined with a refresh token cookie set as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint — allowing an attacker-controlled origin to obtain fresh access and refresh token pairs for a victim session.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet deployed via compromised Langflow instances after exploitation of CVE-2025-34291.
A botnet deployed via compromised Langflow instances after exploitation of the unauthenticated code-validation RCE vulnerability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.