FlowerStorm Phishing Gang KrakVM Obfuscation Campaign | MSSP Advisory

High
DateMay 14, 2026
📋Executive Summary
FlowerStorm phishing-as-a-service operation has adopted KrakVM, an open-source JavaScript virtual machine, to conceal credential theft code in HTML attachments. The attacks target Microsoft 365, Hotmail, and GoDaddy credentials plus MFA codes while supporting adversary-in-the-middle session hijacking. Traditional email security and static analysis tools struggle to detect the virtualized execution environment.
⚠️Why It Matters for MSSPs
Your email security stack may miss these attacks because the virtualized code executes client-side after passing through perimeter defenses. Every client running Microsoft 365 or other targeted services faces credential compromise, and if your monitoring misses the session hijacking, you lose visibility into lateral movement after initial access.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Phishing

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.