Skip to content

Observed infrastructure

Last seven days

First activity
Aug 2, 2026
Last activity
Aug 8, 2026
Feed role
Distribution
Host form
0 IP / 29 hostnames

Leading locations

  • US25

Leading providers

  • Cloudflare, Inc.24
  • HostPapa1

Infrastructure traits

  • Hosting 25
  • Anycast 24

MITRE ATT&CK

FlowerStorm in ATT&CK

19 distinct techniques

Reporting

Research mentioning FlowerStorm

Aug 6
Malware News

Payroll Pirates: Strange New Tides in Business Email Compromise - Malware News - Malware Analysis, News and Indicators

A widespread phishing campaign is compromising Microsoft 365 accounts with adversary-in-the-middle login pages that capture session material even when MFA is enabled, then using those identities to target payroll, HR, finance, and administrative staff across healthcare, education, manufacturing, government, and professional services in the United States, Canada, and Europe. Arctic Wolf said the activity aligns technically and behaviorally with Microsoft-tracked Storm-2755 (also known as Payroll Pirates), with attackers maintaining access through rotating residential proxies and automated session activity roughly every eight hours while quietly collecting mailbox data tied to financial workflows. Reporting also shows the intrusions can progress without additional device compromise, shifting instead into identity-plane lateral movement inside Entra ID and Microsoft 365. After an initial phish, attackers can use stolen session tokens to enumerate the tenant through Microsoft Graph, register a malicious Entra ID application, create a service principal, grant permissions such as Mail.Read and Mail.Send, and access other users’ mailboxes, including executives, before sending fraudulent messages through Graph API that pass SPF and DKIM checks. Defenders were urged to correlate cloud identity, Graph, sign-in, and email telemetry for signals including OfficeHome error 90014, anomalous Outlook sign-ins with Firefox user agents, repeated SessionID reuse across changing IPs and geographies, suspicious app registrations, credential additions to service principals, and unusual application access to user mailboxes.

Aug 6
Arctic Wolf

Payroll Pirates: Strange New Tides in Business Email Compromise - Arctic Wolf

Aug 4
Detect

Attackers Don’t Need Your Devices Anymore They Just Need Your Identity. | by Rohitashokgowd | Aug, 2026 | Detect FYI

Jul 22
Cyber Security News

Hackers Abuse Compromised Outlook Accounts to Steal MFA-Protected Microsoft 365 Sessions

Attackers ran a procurement-themed adversary-in-the-middle phishing campaign against universities, enterprises, multinational institutions, and organizations linked to the European Union and United Nations, using compromised Outlook accounts to resend lures from trusted internal or partner addresses. Victims were directed to fake document download portals with CAPTCHA stages and cloned Microsoft 365 login pages impersonating brands including Microsoft, OpenGov, ConstructConnect, and the European Investment Bank, enabling the theft of credentials, session cookies, and MFA-authenticated tokens in real time. Researchers said the operation relied on reverse-proxy phishing kits including EvilProxy, FlowerStorm/Storm-1167, and Kali365 to bypass MFA and gain access to Outlook, SharePoint, and other Microsoft 365 resources. The infrastructure favored aged or compromised domains, RDGA-style phishing domains, phishing subdomain conventions, and injected PHP content on dormant websites, indicating an effort to evade detection by avoiding newly registered infrastructure; defenders were urged to use DNS and passive DNS visibility, Microsoft 365 sign-in monitoring, and conditional access controls because MFA alone does not stop session hijacking.

Jul 21
Infoblox Threat Intel

Inside a Global Procurement-Themed AiTM Phishing Campaign

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.