FlowCloud
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Proofpoint researchers identified a new, additional malware family named FlowCloud that was also being delivered to U.S. utilities providers. FlowCloud malware, like LookBack, gives attackers complete control over a compromised system.
Proofpoint researchers identified a new, additional malware family named FlowCloud that was also being delivered to U.S. utilities providers. FlowCloud malware, like LookBack, gives attackers complete control over a compromised system.
Proofpoint researchers identified a new, additional malware family named FlowCloud that was also being delivered to U.S. utilities providers. FlowCloud malware, like LookBack, gives attackers complete control over a compromised system.
"TALONITE uses two custom malware families that both feature multiple components known as LookBack and FlowCloud."
Techniques & procedures
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
2 techniquesProofpoint researchers observed phishing campaigns beginning on July 10, 2019 that targeted utility providers across the United States with portable executable (PE) attachments and used subject lines such as “PowerSafe energy educational courses (30-days trial)”... The content of the emails in the November 2019 campaigns impersonated the American Society of Civil Engineers and masqueraded as the legitimate domain asce[.]org.
These campaigns utilized malicious macro-laden documents in order to deliver modular malware to targeted utility providers across the U.S.... threat actors shifted from PE attachments to malicious macro laden Microsoft Word documents that closely resembled the same delivery and installation macros used in LookBack malware campaigns.
Execution
2 techniquesafter an extended period of using PE attachments to deliver FlowCloud in campaigns, the threat actors behind FlowCloud switched to using Microsoft Word documents with malicious macros... FlowCloud uses this same method exactly including identical macro concatenation code.
The earlier LookBack versions of the macro included the payload in numerous privacy enhanced email (“.pem”) files that were dropped when the attachment file is executed by the user.
Persistence
2 techniquesEhStorAuthn.exe extracts the subsequent payload file components and installs them to the directory C:\Windows\Media\SystemPCAXD\ado\fc. This file also sets registry key values that store the keylogger drivers and the malware configuration as the value “KEY_LOCAL_MACHINE\SYSTEM\Setup\PrintResponsor\<2-4>”.
Privilege Escalation
2 techniquesDlcore.dll is a DLL crafted by the threat actors that functions as a shellcode injector pulling the shellcode from a file named rebare.dat... Several legitimate Microsoft Windows files were also used by the malware for thread injection.
Stealth
3 techniquesThe senders of the emails that delivered FlowCloud malware utilized threat actor-controlled domains for delivery which impersonated energy sector training services... The content of the emails in the November 2019 campaigns impersonated the American Society of Civil Engineers and masqueraded as the legitimate domain asce[.]org.
Dlcore.dll is a DLL crafted by the threat actors that functions as a shellcode injector pulling the shellcode from a file named rebare.dat... Several legitimate Microsoft Windows files were also used by the malware for thread injection.
This file is next saved as a portable executable file named “gup.exe” and executed using a version of the certutil.exe tool named “Temptcm.tmp”.
Defense Impairment
1 techniqueEhStorAuthn.exe extracts the subsequent payload file components and installs them to the directory C:\Windows\Media\SystemPCAXD\ado\fc. This file also sets registry key values that store the keylogger drivers and the malware configuration as the value “KEY_LOCAL_MACHINE\SYSTEM\Setup\PrintResponsor\<2-4>”.
Credential Access
1 techniqueCollection
1 techniqueCommand and Control
3 techniquesFlowCloud malware handles configuration updates, file exfiltration, and commands as independent threads utilizing a custom binary C2 protocol.
The FlowCloud version of the macro utilized a previously unobserved macro section to download the payload from a DropBox URL... if it was unable to retrieve the payload from that resource, a catch statement... attempted to retrieve a malware resource from the URL http://ffca.caibi379[.]com/rwjh/qtinfo.txt
FlowCloud malware, like LookBack, gives attackers complete control over a compromised system. Its remote access trojan (RAT) functionality includes the ability to access installed applications, the keyboard, mouse, screen, files, services, and processes with the ability to exfiltrate information via command and control.
Exfiltration
1 techniqueFlowCloud malware handles configuration updates, file exfiltration, and commands as independent threads utilizing a custom binary C2 protocol. The sample we analyzed utilized port 55555 for file exfiltration and port 55556 for all other data.
IOCs tracked for this family
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
FlowCloud is a multi-stage C++ remote access trojan with modular components, keylogging capability, file and process access, screen/keyboard/mouse monitoring, service management, and data exfiltration over a custom binary C2 protocol. It uses legitimate and imitation QQ components during execution and stores encrypted configuration data in the registry.
Custom multi-component malware family used by the TALONITE threat group in spearphishing-driven initial access compromises, supporting intrusion and follow-on operations in the electric sector.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.