A widely active phishing-as-a-service (PhaaS) operation known as FlowerStorm has begun using a browser-based virtual machine to hide credential-stealing code, signaling what researchers say is an escalation in the sophistication of phishing kits that could make the attacks more difficult for traditional email and static analysis tools to detect.
See also: SimpleHelp and ScreenConnect misused for phishing attacks

Researchers at Sublime Security reported in April that they had discovered the campaign, which used KrakVM, an open-source JavaScript virtual machine recently published on GitHub, to hide malicious code delivered via HTML attachments in phishing emails. The campaign targets credentials and multi-factor authentication (MFA) codes for services like Microsoft 365, Hotmail , and GoDaddy, while also supporting adversary-in-the-middle (AiTM) interception techniques designed to hijack authenticated sessions.
The findings highlight how phishing operations are increasingly adopting techniques traditionally associated with complex malware campaigns, including virtualized execution environments and multi-layered obfuscation frameworks. According to the report, victims receive phishing emails containing HTML attachments disguised as voicemail notifications, invoices or vendor communications.
When opened in a browser, the embedded JavaScript immediately launches a credential collection workflow tailored to the victim’s environment. The attack chain uses KrakVM to compile malicious JavaScript into encrypted bytecode, which is executed via a virtual machine running inside the browser. “KrakVM compiles JavaScript into unintelligible bytes,” the researchers wrote, adding that the virtual machine then interprets and executes the payload at runtime.
The approach adds multiple layers of obfuscation designed to complicate static analysis and bypass traditional email security tools. While virtual machine-based obfuscation has long been used in malware packaging and software protection systems, its adoption within large-scale phishing kits appears to be much less common.
Once exposed, the phishing payload loads infrastructure designed to mimic Microsoft 365 and other login portals, while dynamically adapting to targeted users. According to the report, the malware can determine which authentication provider to impersonate, preload victims' email addresses on phishing pages, and customize branding elements such as company logos and backgrounds.
See also: Abuse of Amazon SES for phishing attacks

The phishing kit also lists MFA methods registered on victims' accounts, including Microsoft Authenticator, TOTP, SMS authentication , and voice verification flows. When the victim enters credentials, the kit forwards them to a command-and-control server, which attempts to make a real connection to the targeted service.
If the service requests MFA, the kit presents the victim with a corresponding prompt, captures the response, and forwards it to complete the attacker's session. The researchers said the framework supports real-time AiTM interception, allowing operators to broadcast authentication sessions while collecting credentials and MFA tokens.
The combination of virtual machine-based obfuscation and AiTM-capable payload creates a detection gap for email security tools. Sublime Security said its Autonomous Security Analyst identified the attack as malicious, in part due to the use of “heavy JavaScript obfuscation with custom virtual machine bytecode” from the HTML attachment.
The researchers also noted that both KrakVM and FlowerStorm appear to operate close to their default settings, suggesting that the campaign did not require advanced technical sophistication from the operators. This raises concerns that virtual machine-based obfuscation techniques could quickly spread throughout phishing ecosystems if the tools become easier to operate, the report added.
The campaign has targeted sectors including local government, logistics, retail, communications and real estate, according to the report. Researchers also found infrastructure using domains designed to resemble court systems, business portals and Microsoft-related services. Sublime published 153 breach indicators, including dozens of subdomains in cloud object storage services in locations including Singapore, Bangkok, Frankfurt, Tokyo, Seoul, Jakarta and Ashburn.
See also: Signal phishing: Germany accuses Russia of cyberattacks

The researchers also found domain naming patterns that overlap with previous reports of FlowerStorm, including German-language domains that are assembled from English words to mimic legitimate business names. Sophos had recorded FlowerStorm in December 2024, after the kit emerged following an outage of the Rockstar2FA phishing service. The researchers said they found no evidence linking the KrakVM developer to FlowerStorm's businesses.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
