PULSE NAME
FlowerStorm Phishing Kit Targeting Microsoft Credentials via Cloudflare-Backed Infrastructure
WHITE AlienVault 2026-04-20 Modified: 2026-04-20
7
IOCs
LOW VOLUME
IOCs related to FlowerStorm phishing‑kit–driven campaign that delivers fake Microsoft authentication pages via compromised domains fronted by Cloudflare. The activity abuses legitimate cloud and CDN services for delivery while credential harvesting occurs on attacker‑controlled infrastructure, with incidental contact to Microsoft services during normal browser behavior. that uses its own web servers to target victims' login credentials and access to their personal details and login details on its servers.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (7 / 7 total)
All hostname
TYPEINDICATORDESCRIPTIONCREATED
hostname boysgirlsclubchester.continuousperformance.de 2026-04-20
hostname chestersuplandsd.continuousperformance.de 2026-04-20
hostname chesteruplandsd.continuousperformance.de 2026-04-20
hostname delcofamilyvillage.continuousperformance.de 2026-04-20
hostname fleschlawfirm.continuousperformance.de 2026-04-20
hostname jbsafetyintl.continuousperformance.de 2026-04-20
hostname stevenscollege.continuousperformance.de 2026-04-20