Also known as: tracked as, Storm-2372, broader Midnight Blizzard operations, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Royal Ransomware
FlowerStorm is an advanced phishing‑as‑a‑service operator that leverages adversary‑in‑the‑middle (AITM) techniques against Microsoft 365 services. By impersonating widely used messaging platforms such as WhatsApp, Signal, and Microsoft Teams, the gang lures users into device‑code sign‑ins that allow attackers to capture OAuth tokens via the Microsoft Authentication Broker client ID. These tokens are then traded for Primary Refresh Tokens (PRT), giving the adversary long‑term, persistent access to an organization’s data.\n\nThe platform further registers actor‑controlled devices within Entra ID and employs the Microsoft Graph API to search user mailboxes for credential‑related content, which is subsequently exfiltrated back to their command & control infrastructure. The combination of phishing bait, MFA circumvention, token hijacking, and cloud‑native data theft makes FlowerStorm a significant threat in modern supply‑chain security landscapes.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
FlowerStorm, also known as Storm‑2372 and part of the Midnight Blizzard cluster, operates a phishing‑as‑a‑service platform that specializes in device‑code MFA bypass against Microsoft 365, harvesting authentication tokens and establishing persistent access through Entra ID. Their attacks target a broad spectrum of sectors across North America, Europe, Africa, and the Middle East, with a clear focus on financial gain via credential theft and potential ransomware exploitation.
Goals & Targeting
FlowerStorm’s strategic objectives revolve around large‑scale financial exploitation; its operations aim first to steal organizational credentials through stealthy device‑code phishing, then to maintain persistent footholds for future ransomware or espionage payloads. By targeting high‑value sectors—including government, defense, healthcare, energy, and finance—the actors maximize the perceived value of harvested assets and increase the likelihood of successful monetization. The group’s use of device‑code MFA bypass indicates a sophisticated understanding of cloud security practices, suggesting that its broader operational goals may extend beyond immediate financial gain to include strategic intelligence gathering.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its first documented device‑code phishing activity in August 2024, FlowerStorm has operated as an ongoing threat actor with a high operational tempo. The group routinely exploits legitimate cloud services to gain initial access, establishes persistent footholds via PRTs, and then harvests or exfiltrates credentials using Microsoft Graph API calls. Its victims span diverse sectors—from critical infrastructure and defense to healthcare and finance—across multiple continents. Notably, March 2026 saw Microsoft identify Storm‑2372 as a sub‑cluster of the larger Midnight Blizzard operations, underscoring the actor’s integration within broader threat ecosystems.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis draws on multiple corroborating sources—including Microsoft security blogs, Proofpoint advisories, and malware‑analysis platforms—confirming FlowerStorm’s use of device‑code MFA bypass, token hijacking, and Microsoft Graph API exploitation. Confidence is high in the described tactics, techniques, and operational patterns for initial access, persistence, and credential harvesting. However, gaps remain regarding the full scope of infrastructure, detailed attribution to a nation‑state or individual actors, breadth of associated malware families, and the long‑term evolution of the group’s capabilities.
No campaigns linked yet.
No observed data linked yet.
12
Techniques
44
Tools
0
Campaigns
97
IOCs
0
Observed Data
6
Tactics