logo

FlowerStorm unleashes the KrakVM: PhaaS operators turn to VM-based obfuscation · Blog · Sublime Security

ID: d4e33006-fb34-5fb7-8315-434be2e355cc

STIX ID: report--d4e33006-fb34-5fb7-8315-434be2e355cc

Feed Name: Sublime Security Blog

Threat Score
75/100

Date Published: 2026-05-14

Date Updated: 2026-07-22

...
...

**Executive summary:** This report details an April 2026 phishing campaign combining the KrakVM JavaScript virtual machine as an obfuscation/delivery wrapper with the FlowerStorm PhaaS credential‑harvesting kit; it provides technical VM and deobfuscation analysis, describes FlowerStorm’s AITM MFA interception capability and attack flow, lists numerous IOCs (domains and cloud storage buckets), and assesses the operators as requiring only moderate sophistication while warning of likely broader adoption of KrakVM.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.