FlowerStorm Phishing Kit Targeting Microsoft Credentials via Cloudflare-Backed Infrastructure
Reported 20 Apr 2026 by otx · Severity: medium
IOCs related to FlowerStorm phishing‑kit–driven campaign that delivers fake Microsoft authentication pages via compromised domains fronted by Cloudflare. The activity abuses legitimate cloud and CDN services for delivery while credential harvesting occurs on attacker‑controlled i