HomeSecurityCloudflare Tunnels: They are increasingly being abused by hackers

Cloudflare Tunnels: Increasingly Abused by Hackers

Hackers are increasingly exploiting the legitimate Cloudflare Tunnels feature to create covert HTTPS connections from compromised devices, bypassing firewalls and maintaining a persistent presence.

See also: Microsoft Edge upgrades built-in Cloudflare VPN with 5 GB of data

Cloudflare Tunnels

The technique isn’t entirely new. In January 2023, Phylum reported that threat actors were creating malicious PyPI packages that exploited Cloudflare Tunnels to steal data or gain remote access to devices. However, it appears that more and more threat actors have begun to adopt this tactic, as GuidePoint’s DFIR and GRIT teams reported last week, noting an increase in activity.

CloudFlare Tunnels is a popular feature provided by Cloudflare that allows users to create secure, outbound-only connections to Cloudflare's network for web servers or applications.

Users can create a Tunnel by simply installing one of the available cloudflared clients for Linux, Windows, macOS , and Docker operating systems. This allows for expanded functionality and enhances ease of use. From there, the service is made available to the user over the Internet, using a host computer specified by the user. This computer hosts legitimate usage scenarios, such as resource sharing, testing, and other functions.

CloudFlare Tunnels provide a wealth of features, such as access controls, gateway configurations, group management, and user analytics, giving users a high degree of control within the Tunnel and over exposed services.

See also: Topic Bank: Why isn't the major DDoS attack listed on Cloudflare Radar?

In the GuidePoint report, researchers say that CloudFlare Tunnels is being abused by more hackers for malicious purposes. These purposes include gaining covert permanent access to a victim's network, avoiding detection, and infiltrating data on compromised devices.

hackers

A single command from the victim's device is enough to configure the attacker's discrete communication channel, revealing only the unique Tunnel token. At the same time, the attacker can influence the configuration of a Tunnel, disabling and enabling it as needed, in real time. Since the HTTPS connection and data exchange take place over the QUIC protocol on port 7844, it is unlikely that firewalls or other network protection solutions will detect this process unless they are specifically configured for this purpose.

Additionally, if the attacker wishes to be even more invisible, they can take advantage of Cloudflare's "TryCloudflare" feature, which allows users to create a Tunnel once, without requiring an account.

To make matters worse, according to GuidePoint, Cloudflare's "Private Networks" feature can also be abused, allowing an attacker who has created a tunnel on a client (victim) device to gain remote access to an entire range of internal IP addresses.

To detect unauthorized use of Cloudflare Tunnels, GuidePoint recommends that organizations monitor specific DNS queries (listed in the report) and use non-standard ports, such as port 7844.

See also: Announcement of strategic partnership between Trust-IT LTD and Cloudflare Inc.

Additionally, as Cloudflare Tunnel requires the installation of the 'cloudflare' client, defenders can detect its use by tracking files associated with client versions through their hashes.

Despite the problems caused by the misuse of Cloudflare Tunnels by hackers, they remain an indispensable tool for many businesses and organizations. Cloudflare Tunnels provide a secure and efficient way to create distributed networks, as long as there is adequate management and monitoring to prevent potential malicious use. Users are advised to stay up to date with the latest security developments and use protection tools such as firewalls and systems to address potential threats.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS