FlowCloud
- First seen
- 2018-06-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Profile updated
- 2026-07-07 12:39:30
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:gb
Context
FlowCloud is a remote access trojan with capabilities to exfiltrate data and control infected systems remotely. It is known to target government and technology sectors, primarily focusing on entities in the United States and the United Kingdom.
Detection coverage
- 12 YARA rules
Detection rules
- SEKOIA_Apt_Ta410_Flowcloud_Loader (yara-rule)
- SEKOIA_Apt_Ta410_Flowcloud_Rtti (yara-rule)
- ESET_Apt_Windows_TA410_Flowcloud_Loader_Strings (yara-rule)
- ESET_Apt_Windows_TA410_Flowcloud_Header_Decryption (yara-rule)
- ESET_Apt_Windows_TA410_Flowcloud_Dll_Hijacking_Strings (yara-rule)
- ESET_Apt_Windows_TA410_Flowcloud_Malicious_Dll_Antianalysis (yara-rule)
- ESET_Apt_Windows_TA410_Flowcloud_Pdb (yara-rule)
- ESET_Apt_Windows_TA410_Flowcloud_Shellcode_Decryption (yara-rule)
- ESET_Apt_Windows_TA410_Flowcloud_Fcclient_Strings (yara-rule)
- ESET_Apt_Windows_TA410_Flowcloud_Fcclientdll_Strings (yara-rule)
- ESET_Apt_Windows_TA410_Flowcloud_V5_Resources (yara-rule)
- ESET_Apt_Windows_TA410_Flowcloud_V4_Resources (yara-rule)
Reports & references
- proofpoint.com — Ta410 Group Behind Lookback Attacks Against Us Utilities Sector Returns New (report)
- ESET — Lookback Ta410 Umbrella Cyberespionage Ttps Activity (report)
- ironnet.com — China Cyber Attacks The Current Threat Landscape (report)
- nao-sec.org — Royal Road Redive (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Flowcloud (report)
- static.sstic.org — La Retro Ingnierie De Code Malveillant Dans La Cti Analyse De Levolution Dune Chaine Dinfection.Mp4 (report)
- botconf.eu — Botconf2022 19 Faoucotecyr (report)
- sstic.org — Sstic2024 Article La Retro Ingnierie De Code Malveillant Dans La Cti Analyse De Levolution Dune Chaine Dinfection Meslay (report)
- proofpoint.com — Flowcloud Version 413 Malware Analysis (report)
- sstic.org — Sstic2024 Slides La Retro Ingnierie De Code Malveillant Dans La Cti Analyse De Levolution Dune Chaine Dinfection Meslay (report)
- dragos.com — New Ics Threat Activity Group Talonite (report)