Site icon WinCert

FlowerStorm targets Microsoft 365

<p>A new cybercrime tool&comma; FlowerStorm&comma; has surfaced&comma; giving malicious actors an efficient way to compromise Microsoft 365 accounts&period; This Phishing-as-a-Service &lpar;PaaS&rpar; platform is believed to have connections to Rockstar2FA&comma; a now-defunct service that abruptly vanished in November&period; While the reasons behind Rockstar2FA’s disappearance remain a mystery&comma; experts suspect it wasn’t due to any law enforcement action&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-4593" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2022&sol;04&sol;security-g845aacfe7&lowbar;640&period;jpg" alt&equals;"" width&equals;"640" height&equals;"427" &sol;><&sol;p>&NewLine;<p>Rockstar2FA was notorious for its ability to sidestep two-factor authentication &lpar;2FA&rpar;&comma; allowing attackers to hijack sessions by stealing cookies during login attempts&period; Its streamlined interface and integration with messaging apps like Telegram made it accessible even to less technically skilled criminals&period;<&sol;p>&NewLine;<p>In the aftermath of Rockstar2FA going offline&comma; FlowerStorm emerged&comma; featuring many of the same tools and functionalities&period; This has led cybersecurity researchers to theorize that it might be a successor or revamped version of the previous service&period; Since its debut&comma; FlowerStorm has been used predominantly against organizations in North America and Europe&period; A significant portion of its activity has targeted companies in the United States&comma; with Canada&comma; the United Kingdom&comma; and Australia also seeing considerable impact&period;<&sol;p>&NewLine;<p>The emergence of FlowerStorm highlights the rapid evolution of cybercrime&comma; where tools and services are quickly replaced or rebranded to maintain operations&period; As these threats become more sophisticated&comma; businesses must remain proactive in defending against such attacks&period;<&sol;p>&NewLine;

Exit mobile version