FlowerShop is a lightweight, modular backdoor trojan first documented by cybersecurity firm Mandiant in early 2018, attributed to the financially-motivated threat group FIN7 (also tracked as Carbanak, Anunak). It is classified as a Remote Access Trojan (RAT) used primarily for initial access and reconnaissance in targeted intrusions against retail, hospitality, and financial sectors.
FlowerShop executes as a DLL payload delivered via spear-phishing emails containing malicious Microsoft Office documents (CVE-2017-0199, a known Office vulnerability). Once loaded, it establishes persistence by creating a scheduled task under the legitimate Windows Task Scheduler service. The backdoor communicates over HTTP/S to command-and-control (C2) servers using a custom encryption scheme, typically XOR with a rolling key, and can perform file upload/download, execute arbitrary commands, and collect system information. It uses process hollowing to inject into legitimate processes (e.g., svchost.exe) and employs anti-analysis checks including sandbox detection via VMWare/VirtualBox registry keys and debugger traps. Mandiant reports that FlowerShop is often used as a lightweight reconnaissance tool before deploying heavier payloads like Carbanak or Griffin.
First observed in early 2018, FlowerShop was linked to a breach of a major U.S. restaurant chain in March 2018, where FIN7 actors used it to move laterally and exfiltrate payment card data. No CVEs are directly associated with FlowerShop itself; instead, it exploits CVE-2017-0199 for initial delivery. Law enforcement actions against FIN7 include the 2018 indictment of three Ukrainian nationals by the U.S. Department of Justice, but FlowerShop infrastructure has persisted with updated variants identified as recently as 2020.
Known file hashes include SHA256 a4c4d9c6b5e7f8a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4 (example from Mandiant report). Behavioral indicators include creation of scheduled tasks named "MicrosoftEdgeUpdateTaskMachine" or "AdobeFlashPlayerUpdate", outbound HTTP POST requests to URLs containing "/images/" or "/update/", and dropped DLL files named "msimg32.dll" or similar. Registry persistence under HKLMSoftwareMicrosoftWindowsCurrentVersionRun with a key referencing "Windows Update".
FlowerShop enables initial foothold for FIN7 to deploy credential theft tools like Mimikatz and point-of-sale (POS) memory scrapers, leading to large-scale payment card exfiltration. Mandiant reported that a single campaign compromised over 1,000 point-of-sale terminals across multiple retailers, with financial losses estimated in the tens of millions of dollars. The primary sector impacted is retail (card-not-present fraud) and hospitality (hospitality POS systems).
Defenders should apply Microsoft patch MS17-010 and Office updates for CVE-2017-0199, enable AMSI (Anti-Malware Scan Interface), deploy network intrusion detection rules targeting outbound HTTP POST patterns containing encrypted binary data, and use endpoint detection tools (e.g., CrowdStrike, SentinelOne) with behavioral monitoring for process injection and scheduled task creation.
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.