Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
FlowerStorm is a phishing-as-a-service platform, not a newly discovered Microsoft 365 software vulnerability. It is associated with fake Microsoft 365 sign-in pages and adversary-in-the-middle (AiTM) attacks that can capture credentials and authenticated sessions. That can let an attacker get past some forms of multifactor authentication (MFA)—but it does not make all MFA useless.
FlowerStorm was reported as emerging around mid-2024, so it is better described now as an established and evolving threat than as a brand-new one. The practical defenses are to verify sign-in requests, use phishing-resistant authentication where possible, and investigate sessions and account changes—not just passwords—if someone enters credentials on a suspicious page.
What is FlowerStorm?
FlowerStorm is a criminal phishing-as-a-service (PhaaS) platform: a service that supplies or automates phishing infrastructure for operators who may not build their own. Reporting describes it as targeting Microsoft 365 with convincing sign-in pages and AiTM techniques that can steal credentials and session material. Darktrace’s investigation also describes similarities between FlowerStorm and the earlier Rockstar2FA service.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The name describes a platform or activity cluster in available reporting; it does not identify every person using it or prove that every similar Microsoft-themed phishing page is part of FlowerStorm. Nor does it mean Microsoft 365 has been breached or that attackers have exploited a newly disclosed flaw in Microsoft Entra ID or Exchange Online. The described attack abuses phishing and authentication workflows.
#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Microsoft 365 accounts are attractive targets because one identity may provide access to email, files, Teams, SharePoint, OneDrive, and connected business applications. A compromised account can expose sensitive data or give an attacker a trusted address from which to target colleagues and partners.
How an AiTM phishing attack works
- A lure creates urgency. A message may imitate an account alert, shared document, voicemail, password warning, invoice, or IT request. These are common phishing themes, not unique FlowerStorm identifiers.
- The link leads to a lookalike page. The page may copy Microsoft branding and sign-in steps. The address bar—not the logo or padlock—is the useful place to check whether the site is actually on a Microsoft domain or another domain your organization expects.
- The phishing service relays the sign-in. In a conventional credential-phishing attack, the site collects a password for later use. In an AiTM attack, a server can pass the victim’s authentication traffic between the fake page and the real service.
- The victim completes MFA. The user may approve a prompt or enter a code while believing the sign-in is legitimate. If the relay captures the authenticated session, the attacker may obtain usable session material—not just a password.
- The attacker attempts account access and persistence. Possible follow-on actions include reading email, searching files, creating forwarding rules, changing authentication methods, granting an application access, or sending phishing messages from the account. These are possible outcomes, not a fixed FlowerStorm playbook.
Darktrace reported a FlowerStorm-linked case investigated in March 2025 that included unusual Microsoft 365 and other SaaS logins, password resets, and attempted privilege escalation. Those observations are useful hunting leads, but one incident does not establish what every FlowerStorm operator does.
What users should check before signing in
A polished page and HTTPS connection are not proof that a sign-in page belongs to Microsoft. Before entering a password or approving a prompt:
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Check the full domain in the browser’s address bar, especially after a redirect or shortened link.
- Be wary of a sign-in reached through an unexpected email, Teams message, document share, or phone request.
- Stop if a page asks you to sign in again unexpectedly, or if an MFA request appears when you did not initiate one.
- Do not approve an unexpected prompt or share a one-time code with someone claiming to be IT.
- Verify an urgent request through a separate, known-good channel—such as a saved help-desk number or your organization’s normal reporting process.
- Report the message rather than forwarding it casually, and tell your IT or security team if you already entered credentials or approved MFA.
Microsoft’s phishing guidance covers reporting suspicious Outlook messages and Teams messages. In Teams, the documented reporting flow includes More options → More actions → Report this message; the precise controls can vary by client and organization settings.
Does MFA stop FlowerStorm?
MFA remains essential: it blocks many attacks that rely on a stolen password alone. But MFA that can be relayed through a fake sign-in flow may not stop an AiTM attack, because the attacker is trying to capture the resulting authenticated session. Push approvals, number matching, SMS codes, and one-time codes are useful controls, but they are not equivalent to phishing-resistant authentication.
Where supported, organizations should prioritize FIDO2 security keys, passkeys, or other WebAuthn-based phishing-resistant methods, especially for administrators and people with access to financial, customer, or sensitive business data. Pair them with Conditional Access authentication-strength policies and sensible device and sign-in-risk controls. Phishing-resistant authentication substantially reduces AiTM risk; it does not prevent every route to compromise, such as endpoint malware or account-recovery abuse.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Do not disable MFA because it can be targeted. Keep MFA enabled, reduce reliance on methods that can be phished for high-risk accounts, and make recovery procedures strong enough that they do not undermine the stronger sign-in method.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →What Microsoft 365 administrators should do
No single product setting should be treated as a FlowerStorm blocker. The goal is layered protection across email, identity, collaboration, and post-sign-in activity.
Harden identity
- Require MFA wherever supported, and prioritize phishing-resistant methods for privileged accounts, executives, finance staff, help-desk personnel, and other high-value users.
- Review Conditional Access coverage, exclusions, authentication strengths, sign-in risk policies, device requirements, and emergency accounts. Test policy changes to avoid accidental lockouts.
- Block legacy authentication where possible and review any exceptions.
- Use separate, strongly protected administrator accounts; limit standing administrative privileges.
Microsoft’s Conditional Access documentation explains the policy framework. Available features depend on licensing, tenant configuration, and administrator permissions.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Reduce phishing exposure
- Review Defender for Office 365 anti-phishing and impersonation policies, mailbox intelligence, Safe Links, and Safe Attachments where licensed.
- Configure user message reporting and make sure staff know how to report suspicious email and Teams messages.
- Review external collaboration and Teams communication controls so users can recognize and report unexpected contact.
- Use the Tenant Allow/Block List carefully. Microsoft documents blocking malicious URLs and domains, but broad or poorly reviewed allow-list entries can weaken protection.
Microsoft Defender for Office 365 reporting includes views for phishing, URL protection, Safe Links, compromised users, spoofing, and post-delivery activity, subject to plan and configuration. Microsoft’s reporting documentation notes the available report areas; some dashboard data may lag, so a recent incident should not be ruled out solely because a report is incomplete. Administrators can submit suspicious messages, URLs, and attachments through the Defender portal’s Submissions page.
Monitor beyond the inbox
Review identity and SaaS activity as well as message delivery. Useful sources include Entra sign-in logs, unified audit logs, Exchange message trace, Defender Explorer or real-time detections, Safe Links click data, OAuth application audit events, mailbox-rule changes, authentication-method changes, Conditional Access results, risky-user detections, Teams external-message activity, and endpoint telemetry if a file or remote-access tool was involved.
Free tools Windows power users keep installed
One-click scans. No signup required.
Look for clusters of suspicious events: a phishing click followed by a successful sign-in; unfamiliar IP addresses, locations, applications, or browser patterns; unexpected password resets or new authentication methods; new forwarding rules or delegates; unusual OAuth consent; large mailbox searches or downloads; and messages sent from an account whose owner denies sending them. No single IP address, domain, or sign-in anomaly is a definitive FlowerStorm signature, and infrastructure can change quickly.
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
What to do if someone entered credentials or approved an unexpected prompt
Treat credential entry or an unexpected MFA approval as a possible compromise. Contact the organization’s security team using a known-good channel and act promptly. If malware or remote access is also suspected, isolate the device from untrusted networks and follow the incident-response team’s instructions.
- Secure the account from a clean device. Reset the password, and avoid using the suspected device until it has been assessed.
- Revoke sessions and tokens. Ask administrators to invalidate active sessions and refresh tokens. A password change alone may not end an attacker’s existing session.
- Check authentication methods. Review and remove methods the user did not add, and inspect recent security-information changes.
- Look for persistence. Review mailbox forwarding and inbox rules, delegates, sent mail, OAuth application consent and grants, and any suspicious service-principal or privilege changes.
- Review sign-ins and activity. Check unfamiliar IPs, locations, user agents, applications, and sign-in patterns, then examine activity in Exchange, SharePoint, OneDrive, Teams, and connected services.
- Contain the spread. Search for and remove malicious messages sent by the account where appropriate. Notify recipients and external partners if they may have received a fraudulent message.
- Preserve evidence and escalate. Review audit logs and involve incident response, legal, cyber insurance, or law enforcement as required by your organization and applicable obligations.
A password reset is only one part of recovery. An attacker may still have a session, an added authentication method, an application grant, or a mailbox rule that needs separate investigation and removal.
FlowerStorm and other names: related, not interchangeable
Similar branding or shared techniques do not prove that separate services and threat groups are the same operation. Keep these names distinct:
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match| Name | What reporting describes | What not to assume |
|---|---|---|
| FlowerStorm | A PhaaS platform associated with Microsoft 365-themed AiTM phishing and credential or session theft. | It is not a Microsoft-tracked actor name, a confirmed software vulnerability, or a label for every Microsoft 365 phishing campaign. |
| Rockstar2FA | A separate service with reported similarities to FlowerStorm in phishing portals, targeting, and infrastructure patterns. | Similarity does not prove common operators. |
| Storm-1811 | A Microsoft-tracked criminal group linked to help-desk impersonation, Teams, Quick Assist, EvilProxy, and ransomware-related activity in Microsoft’s reporting. | Available sources do not establish that Storm-1811 operates FlowerStorm. |
| Storm-2372 | A separate Microsoft-tracked campaign involving device-code phishing; Microsoft reported activity beginning in August 2024. | Device-code phishing and FlowerStorm’s AiTM activity are different techniques, even though both can challenge assumptions about MFA. |
| RaccoonO365 / Storm-2246 | A separate subscription-based phishing service. Microsoft said in September 2025 that it had seized 338 websites associated with RaccoonO365 and reported credential theft at scale. | Those figures concern RaccoonO365, not FlowerStorm. |
See Microsoft’s reporting on Storm-1811, Storm-2372, and RaccoonO365 for the separate activity Microsoft describes.
The practical takeaway for organizations
Do not look for a product that promises to block one named phishing service. Configure the email and identity controls you already have, move high-risk users toward phishing-resistant authentication, and make sure your team can revoke sessions and investigate account persistence. Those measures address FlowerStorm’s described attack path and remain useful when a campaign changes its domains, lures, or operator.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

