Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors FlowerStorm

Also known as: tracked as, Storm-2372, broader Midnight Blizzard operations, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Royal Ransomware

Description

FlowerStorm is an advanced phishing‑as‑a‑service operator that leverages adversary‑in‑the‑middle (AITM) techniques against Microsoft 365 services. By impersonating widely used messaging platforms such as WhatsApp, Signal, and Microsoft Teams, the gang lures users into device‑code sign‑ins that allow attackers to capture OAuth tokens via the Microsoft Authentication Broker client ID. These tokens are then traded for Primary Refresh Tokens (PRT), giving the adversary long‑term, persistent access to an organization’s data.\n\nThe platform further registers actor‑controlled devices within Entra ID and employs the Microsoft Graph API to search user mailboxes for credential‑related content, which is subsequently exfiltrated back to their command & control infrastructure. The combination of phishing bait, MFA circumvention, token hijacking, and cloud‑native data theft makes FlowerStorm a significant threat in modern supply‑chain security landscapes.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Telecommunications
Education
Healthcare
Non profit
Critical infrastructure
Information technology
Hospitality
Media
Manufacturing
Retail
Energy
Oil gas
Aerospace
Maritime
Nuclear
Entertainment
Gaming
Food agriculture
Construction
Transportation

Targeted Countries / Regions

RU
CN
DE
US
IN
UA
GB
KP
IR
PK
BY
PL
TW
CA
AU

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 15 hours ago

Executive Summary

FlowerStorm, also known as Storm‑2372 and part of the Midnight Blizzard cluster, operates a phishing‑as‑a‑service platform that specializes in device‑code MFA bypass against Microsoft 365, harvesting authentication tokens and establishing persistent access through Entra ID. Their attacks target a broad spectrum of sectors across North America, Europe, Africa, and the Middle East, with a clear focus on financial gain via credential theft and potential ransomware exploitation.

Goals & Targeting

FlowerStorm’s strategic objectives revolve around large‑scale financial exploitation; its operations aim first to steal organizational credentials through stealthy device‑code phishing, then to maintain persistent footholds for future ransomware or espionage payloads. By targeting high‑value sectors—including government, defense, healthcare, energy, and finance—the actors maximize the perceived value of harvested assets and increase the likelihood of successful monetization. The group’s use of device‑code MFA bypass indicates a sophisticated understanding of cloud security practices, suggesting that its broader operational goals may extend beyond immediate financial gain to include strategic intelligence gathering.

Enhanced Description

Key Capabilities

  • Device code phishing campaigns that bypass MFA
  • Adversary‑in‑the-Middle attacks against Microsoft 365 services
  • Impersonation of third‑party messaging platforms (WhatsApp, Signal, Microsoft Teams)
  • Harvesting authentication tokens (refresh token, Primary Refresh Token) via the Microsoft Authentication Broker client ID
  • Registration of actor‑controlled devices in Entra ID for persistence
  • Use of the Microsoft Graph API to search user messages and exfiltrate content
  • Credential harvesting and token hijacking

MITRE ATT&CK Tactics

Initial Access
Credential Access
Execution
Persistence
Discovery
Defense Evasion
Exfiltration

ATT&CK Techniques

T1041
T1048
T1133
T1190
T1566
T1566.001
T1566.003
T1654
T1657
T1204

Software / Tooling

FlowerStorm
Storm-2372
BlackCat
RansomHub
Royal Ransomware
Cobalt Strike
PowerShell
AnyDesk
Quick Assist

Campaigns & Victims

Since its first documented device‑code phishing activity in August 2024, FlowerStorm has operated as an ongoing threat actor with a high operational tempo. The group routinely exploits legitimate cloud services to gain initial access, establishes persistent footholds via PRTs, and then harvests or exfiltrates credentials using Microsoft Graph API calls. Its victims span diverse sectors—from critical infrastructure and defense to healthcare and finance—across multiple continents. Notably, March 2026 saw Microsoft identify Storm‑2372 as a sub‑cluster of the larger Midnight Blizzard operations, underscoring the actor’s integration within broader threat ecosystems.

IOC Patterns

  • Domain-based phishing URLs such as login.microsoftonline.com mimic sites
  • Device code authentication flow used in phishing attempts
  • Mimicked messaging app sign‑in prompts (WhatsApp, Signal, Microsoft Teams)
  • Exfiltration via Microsoft Graph API calls
  • Use of Microsoft Authentication Broker client ID in malicious payloads

Recommended Actions

  • Revoke user Refresh Tokens via Azure AD revokeSignInSessions to remove persistent access
  • Deploy Conditional Access policies that require full re‑authentication and block device‑code sign‑ins for privileged accounts
  • Disable or restrict the Microsoft Authentication Broker client ID for untrusted applications
  • Monitor Azure AD for anomalous device registration events and suspicious authentication flows
  • Implement DNS filtering and domain blocking against phishing sites identified in IOC patterns
  • Enforce MFA with multi‑factor verification beyond device code, such as push notifications or phone call

Suggested Tags

phishing-as-a-service
adversary-in-the-middle
Microsoft 365
MFA bypass
device code phishing
Storm-2372
Midnight Blizzard
microsoft-graph-api-exploitation
token hijacking
nation-state-actor
Russian interest
persistent-access-prt
credential harvesting
Entra ID device registration
government
NGO
IT services
technology
defense
telecommunications
health
Higher Education
energy/Oil and gas
Europe
North America
Africa
Middle East
financial gain
ransomware
social engineering

Confidence Assessment

The analysis draws on multiple corroborating sources—including Microsoft security blogs, Proofpoint advisories, and malware‑analysis platforms—confirming FlowerStorm’s use of device‑code MFA bypass, token hijacking, and Microsoft Graph API exploitation. Confidence is high in the described tactics, techniques, and operational patterns for initial access, persistence, and credential harvesting. However, gaps remain regarding the full scope of infrastructure, detailed attribution to a nation‑state or individual actors, breadth of associated malware families, and the long‑term evolution of the group’s capabilities.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 20

References

  1. www.microsoft.com — Cited by web research for: Storm-2372
  2. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  3. www.esentire.com — Cited by web research for: CALENDAR
  4. www.sophos.com — Cited by web research for: curl
  5. https://any.run/malware-trends/blindeagle/ — Cited by AI analysis.
  6. https://medium.com/@anyrun/how-phishing-is-targeting-germanys-economy-active-threats-from-finance-to-manuf — Cited by AI analysis.
  7. https://www.proofpoint.com/us/bl — Cited by AI analysis.

Intel Summary

12

Techniques

44

Tools

0

Campaigns

97

IOCs

0

Observed Data

6

Tactics

Tags

Critical Infrastructure
Phishing
APT
phishing
financial-sector
phishing-as-a-service
adversary-in-the-middle
Microsoft 365
MFA bypass
device code phishing
Storm-2372
Midnight Blizzard
microsoft-graph-api-exploitation
token hijacking
nation-state-actor
Russian interest
persistent-access-prt
credential harvesting
Entra ID device registration
government
NGO
IT services
technology
defense
telecommunications
health
Higher Education
energy/Oil and gas
Europe
North America
Africa
Middle East
financial gain
ransomware
social engineering

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.