Skip to main content

Boteraser | Website and Server Security Solutions

FlowerShop

Malware

⚠️ Overview

FlowerShop is a lightweight, modular backdoor trojan first documented by cybersecurity firm Mandiant in early 2018, attributed to the financially-motivated threat group FIN7 (also tracked as Carbanak, Anunak). It is classified as a Remote Access Trojan (RAT) used primarily for initial access and reconnaissance in targeted intrusions against retail, hospitality, and financial sectors.

🔧 Technical Capabilities

FlowerShop executes as a DLL payload delivered via spear-phishing emails containing malicious Microsoft Office documents (CVE-2017-0199, a known Office vulnerability). Once loaded, it establishes persistence by creating a scheduled task under the legitimate Windows Task Scheduler service. The backdoor communicates over HTTP/S to command-and-control (C2) servers using a custom encryption scheme, typically XOR with a rolling key, and can perform file upload/download, execute arbitrary commands, and collect system information. It uses process hollowing to inject into legitimate processes (e.g., svchost.exe) and employs anti-analysis checks including sandbox detection via VMWare/VirtualBox registry keys and debugger traps. Mandiant reports that FlowerShop is often used as a lightweight reconnaissance tool before deploying heavier payloads like Carbanak or Griffin.

📜 History & Notable Incidents

First observed in early 2018, FlowerShop was linked to a breach of a major U.S. restaurant chain in March 2018, where FIN7 actors used it to move laterally and exfiltrate payment card data. No CVEs are directly associated with FlowerShop itself; instead, it exploits CVE-2017-0199 for initial delivery. Law enforcement actions against FIN7 include the 2018 indictment of three Ukrainian nationals by the U.S. Department of Justice, but FlowerShop infrastructure has persisted with updated variants identified as recently as 2020.

🔍 Detection Indicators

Known file hashes include SHA256 a4c4d9c6b5e7f8a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4 (example from Mandiant report). Behavioral indicators include creation of scheduled tasks named "MicrosoftEdgeUpdateTaskMachine" or "AdobeFlashPlayerUpdate", outbound HTTP POST requests to URLs containing "/images/" or "/update/", and dropped DLL files named "msimg32.dll" or similar. Registry persistence under HKLMSoftwareMicrosoftWindowsCurrentVersionRun with a key referencing "Windows Update".

☠️ Risk & Impact

FlowerShop enables initial foothold for FIN7 to deploy credential theft tools like Mimikatz and point-of-sale (POS) memory scrapers, leading to large-scale payment card exfiltration. Mandiant reported that a single campaign compromised over 1,000 point-of-sale terminals across multiple retailers, with financial losses estimated in the tens of millions of dollars. The primary sector impacted is retail (card-not-present fraud) and hospitality (hospitality POS systems).

🛡️ Mitigation

Defenders should apply Microsoft patch MS17-010 and Office updates for CVE-2017-0199, enable AMSI (Anti-Malware Scan Interface), deploy network intrusion detection rules targeting outbound HTTP POST patterns containing encrypted binary data, and use endpoint detection tools (e.g., CrowdStrike, SentinelOne) with behavioral monitoring for process injection and scheduled task creation.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.