Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Qilin Ransomware adds the “Call Lawyer” function to pressure victims for big ransom

June 20, 2025

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Rockstar2FA’s takedown contributes to FlowerStorm’s Phishing-as-A-Service expansion
Global Security

Rockstar2FA’s takedown contributes to FlowerStorm’s Phishing-as-A-Service expansion

AdminBy AdminDecember 23, 2024No Comments3 Mins Read
FlowerStorm Phishing-as-a-Service
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


December 23, 2024Ravi LakshmananPhishing / Cybercrime

Phishing as a service by FlowerStorm

A break in the Phishing as a Service (PhaaS) toolkit was caused. Rockstar 2FA led to a rapid uptick in activity due to another nascent offering called FlowerStorm.

“It appears that the group (Rockstar2FA) running the service has experienced at least a partial collapse of their infrastructure, and pages related to the service are no longer accessible,” Sophos said. said in a new report published last week. “It appears that this was not due to a takedown, but due to some technical failure in the server side of the service.”

Rockstar2FA was documented for the first time by Trustwave late last month as a PhaaS service that allows criminals to launch phishing attacks capable of harvesting Microsoft 365 account credentials and session cookies, thereby bypassing multi-factor authentication (MFA) protections.

Cyber ​​security

The service is billed as an updated version of a Microsoft-tracked DadSec phishing kit called Storm-1575. It was found that most phishing pages are hosted on .com, .de, .ru. and .moscow top-level domains, although the use of .ru domains is believed to have declined over time.

Phishing as a service by FlowerStorm

Rockstar2FA appears to have experienced a technical failure on November 11, 2024, when redirects to intermediate decoy pages caused Cloudflare timeout errors and failed to load fake login pages.

While it’s unclear what caused the failure, the void left by the PhaaS toolkit led to a surge in phishing activity linked to FlowerStorm, which has been active since at least June 2024.

Phishing as a service by FlowerStorm

Sophos said the two services share similarities when it comes to the format of phishing portal pages and the methods used to connect to back-end servers to collect credentials, raising the possibility of a common origin. They also abuse Cloudflare turnstile to ensure that incoming requests to the page are not from bots.

There are suspicions that the November 11 failure represents either a strategic shift in one of the groups, a change in the personnel running them, or a deliberate attempt to separate the twin operations. At this stage, there is no definitive evidence linking the two services.

Cyber ​​security

The countries that use FlowerStorm the most include the United States, Canada, the United Kingdom, Australia, Italy, Switzerland, Puerto Rico, Germany, Singapore, and India.

“The service sector most affected is the services industry, with a particular focus on companies that provide engineering, construction, real estate, legal services and consulting,” Sophos said.

In any case, the obtained data once again illustrates the long-term trend of attackers using cybercriminal services and commercial tools to carry out large-scale cyberattacks without even requiring special technical knowledge.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Qilin Ransomware adds the “Call Lawyer” function to pressure victims for big ransom

June 20, 2025

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Qilin Ransomware adds the “Call Lawyer” function to pressure victims for big ransom

June 20, 2025

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Qilin Ransomware adds the “Call Lawyer” function to pressure victims for big ransom

June 20, 2025

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.