HomeSecurityFlowerStorm: New phishing platform steals Microsoft credentials

FlowerStorm: New phishing platform steals Microsoft credentials

A new phishing-as-a-service platform, called “FlowerStorm” and targeting Microsoft 365 accounts, is becoming increasingly popular, filling the void left behind by the sudden shutdown of the service Rockstar2FA.

FlowerStorm phishing Rockstar2FA

The Rockstar2FA platform was first analyzed by Trustwave in late November 2024 and facilitated large-scale adversary-in-the-middle (AiTM) attacks aimed at stealing Microsoft 365 credentials

The service offered advanced analysis evasion mechanisms, a user-friendly admin panel, and numerous phishing options. Cybercriminals could use the service by paying $200 for two weeks.

See also: New phishing campaign “HubPhish” targets European companies

According to Sophos researchers Sean Gallagher and Mark Parsons, Rockstar2FA suffered a partial infrastructure collapse on November 11, 2024, rendering many of the service's pages inaccessible. It is believed that this was not the result of law enforcement action, but rather a technical failure.

A few weeks later, the FlowerStorm phishing service, which first appeared in June 2024, began to become more popular.

Is there a chance this is a rebrand of Rockstar2FA?

Sophos discovered that the new phishing-as-a-service, FlowerStorm, shares many common features with Rockstar2FA. Researchers identified several similarities, suggesting a common origin or functional overlap:

  • Both platforms use phishing portals that mimic legitimate login pages (e.g. Microsoft) to collect credentials and MFA tokens. These rely on backend servers hosted on domains such as .ru and .com. According to the researchers, Rockstar2FA used randomized PHP scripts, while FlowerStorm standardized on next.php.
  • Microsoft 365 credential collection methods are quite similar. Both platforms support email validation and MFA authentication through their backend systems.
  • The HTML structure of the phishing pages is also very similar. Rockstar2FA used car themes, while FlowerStorm turned to botanical themes, but the underlying design remains similar (random text in comments, Cloudflare “turnstile” security features, etc.).
  • Domain registration and hosting patterns overlap significantly, with heavy use of domains.ru and .com and Cloudflare services. Their activity patterns showed synchronized increases and decreases until the end of 2024, indicating possible coordination.
  • The researchers observed that both platforms made operational errors that exposed backend systems and demonstrated high scalability. The Rockstar2FA phishing service operated over 2,000 domains, while FlowerStorm expanded very quickly after the Rockstar2FA collapse, which could indicate a common framework.

See also: Sharp increase in phishing attacks in the second half of 2024

Microsoft credentials

“ We cannot link Rockstar2FA and FlowerStorm with high confidence, but we can note that the phishing kits at least reflect a common origin due to the similar content ,” Sophos concludes

“The similar domain registration patterns could be a reflection of the FlowerStorm and Rockstar collaboration, although it is also possible that these patterns are driven more by market forces than by the platforms themselves“.

The risk is constantly increasing

In reality, it may not matter that much whether the phishing service is related to Rockstar2FA. What is certain is that users and organizations are facing another risk.

Sophos data shows that approximately 63% of organizations and 84% of users targeted by FlowerStorm are based in the United States.

The most targeted sectors are services (33%), construction (21%), retail (12%) and financial services (8%).

Protection

Users should be wary of messages they receive from strangers or from supposedly well-known companies. Many times, phishing attacks start with a simple message asking for the user's login details.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

FlowerStorm: New phishing platform steals Microsoft credentials

Next, they should regularly update their software, including the operating system and applications. These updates often include security that can protect the user from the latest threats.

See also: Hackers exploit Google Calendar for phishing attacks

Using reliable security software, such as an antivirus or security app, can help protect against attacks. These tools can identify and block suspicious websites or messages that are trying to steal user information.

Finally, users should be careful when downloading applications from the internet. Many times, applications that seem innocent may contain hidden code that can steal user information or cause other security threats.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS