FlowerStorm unleashes the KrakVM: PhaaS operators turn to VM-based obfuscation · Blog · Sublime Security
ID: d4e33006-fb34-5fb7-8315-434be2e355cc
STIX ID: report--d4e33006-fb34-5fb7-8315-434be2e355cc
Feed Name: Sublime Security Blog
**Executive summary:** This report details an April 2026 phishing campaign combining the KrakVM JavaScript virtual machine as an obfuscation/delivery wrapper with the FlowerStorm PhaaS credential‑harvesting kit; it provides technical VM and deobfuscation analysis, describes FlowerStorm’s AITM MFA interception capability and attack flow, lists numerous IOCs (domains and cloud storage buckets), and assesses the operators as requiring only moderate sophistication while warning of likely broader adoption of KrakVM.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
