TFlower
- First seen
- 2019-09-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 14:23:57
Targeted industries: professional-services financial-services retail-and-hospitality healthcare-and-pharmaceutical
Context
TFlower is a type of ransomware known for encrypting files on infected systems and demanding a ransom for decryption. It has been reported targeting various industries, notably affecting small to mid-sized businesses. TFlower ransomware typically spreads through unsecured remote desktop services and phishing emails.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Tflower_Auto (yara-rule)
Reports & references
- sygnia.co — Mata Framework (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Tflower (report)
- cyber.gc.ca — Tflower Ransomware Campaign (report)
- bleepingcomputer.com — Tflower Ransomware The Latest Attack Targeting Businesses (report)