#FlowerPower
Malware/Tool
2020-09-30 • To catch a Banshee: How Kimsuky’s tradecraft betrays its complementary campaigns and mission
FlowerPower is a script-based malware family used by Kimsuky since at least 2020. Campaigns stored components in GitHub repositories and sometimes uploaded stolen victim information to the same service. Operators fragmented scripts to alter the malware's structure between deployments, complicating straightforward comparison of individual versions. FlowerPower was also distributed alongside RandomQuery, while related infection chains involved QuasarRAT or xRAT. Its observed use combines staged script execution, flexible component hosting, and data theft within Kimsuky operations.
-
9
Tagged Reports
-
3
Unique Authors
-
1,375
Active Days