Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators FlowerStorm unleashes the KrakVM: PhaaS operators turn to VM-based obfuscation

valid.seashellshoetreasures.de

TLP:CLEAR
Active

Domain

Description

FlowerStorm is a widely known Phishing-As-A-Service (PhaaS) attack kit that has been active since at least mid-2024, increasingly in large scale campaigns. FlowerStorm performs targeted, complex collection of a victim’s credentials, including the management of multi-factor authentication (MFA).

Sightings (0)

No sightings recorded yet

Details

Name / Label
FlowerStorm unleashes the KrakVM: PhaaS operators turn to VM-based obfuscation
Pattern Type
STIX
Confidence
75%
Valid From
May 21, 2026 03:05
Total Sightings
0
Added
May 21, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of valid.seashellshoetreasures.de

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.