A new Microsoft 365 phishing service has emerged, so be on your guard


  • Researchers said Rockstar2FA went silent in November 2024
  • But soon after, a new PaaS emerged, with a partially overlapping infrastructure.
  • The new PaaS is called FlowerStorm and is aimed at Microsoft365 accounts

Cybersecurity researchers at Sophos have warned that a new phishing-as-a-service (PaaS) tool has emerged, allowing threat actors to easily search for people’s Microsoft 365 credentials.

This tool is called FlowerStorm and could have emerged from the (defunct) Rockstar2FA, the company revealed, noting how in November, Rockstar2FA detections “suddenly went silent.”

Leave a Comment

Your email address will not be published. Required fields are marked *