logo

New FlowerStorm Microsoft phishing service fills void left by Rockstar2FA

ID: 816a74de-16a0-5146-9621-9093ad9b280f

STIX ID: report--816a74de-16a0-5146-9621-9093ad9b280f

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-12-21

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

FlowerStorm is a growing phishing-as-a-service platform that rapidly filled the gap left by the partial collapse of Rockstar2FA; it supports AiTM attacks against Microsoft 365, harvests credentials and MFA tokens, and displays strong similarities in infrastructure and phishing kit content to Rockstar2FA. Sophos telemetry shows heavy targeting in the United States across services, manufacturing, retail, and financial sectors; the report highlights domain/hosting patterns, shared TTPs, and defensive recommendations such as FIDO2-resistant MFA, email filtering, and DNS blocking of suspicious TLDs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.