HomeSecurityCloudflare Tunnels Abused in New Malware Campaign

Cloudflare Tunnels Abused in New Malware Campaign

Securonix has uncovered a malware distribution campaign that abuses Cloudflare Tunnel to host malicious files on subdomains controlled by the attackers.

See also: Cloudflare blocks 7.3 Tbps DDoS attack

Cloudflare Tunnel malware

The campaign, dubbed Serpentine#Cloud, relies on a complex infection chain involving shortcut files (LNK) and disguised scripts, aiming to install a Python-based loader capable of executing a Donut-packaged PE payload directly into memory.

Early attacks associated with this campaign used URL files to execute the payloads. However, a shift was observed to using BAT files, often within ZIP archives, to download and execute the payloads via a Cloudflare tunnel.

In more recent attacks, LNK files disguised as PDF documents are used to distribute malicious payloads. These files are sent to victims via phishing emails with payment or invoice-related themes, which contain links to ZIP archives containing the LNK file.

Cloudflare tunnels offer remote access to resources like VPNs, but cybercriminals are increasingly abusing them to distribute malware. This allows them to remain anonymous and bypass protection and detection measures, as the traffic appears to come from a legitimate service.

See also: 2024: Cloudflare blocked a record number of DDoS attacks

In the context of the Serpentine#Cloud campaign , it was observed that the LNK file sent to potential victims triggers a complex infection chain that uses robocopy to retrieve a Windows Script File (WSF) from a remote WebDAV share hosted via the Cloudflare Tunnel infrastructure. Script execution then continues via the Windows Script Host (WSH) .

Cloudflare Tunnels Abused in New Malware Campaign
Cloudflare Tunnels Abused in New Malware Campaign

The infection process continues by executing a disguised batch file, which retrieves Python -based malware , establishes persistence on the system, hides the malware's folders, and then executes it.

The malware acts as a shellcode loader, using the Early Bird APC injection to silently execute shellcode within a new process, Securonix explains. The executed shellcode is eventually decrypted into a Windows PE, which is usually either a common or open-source Remote Access Trojan (RAT)such as AsyncRAT or RevengeRAT.

A related and important point that emerges from the Serpentine#Cloud is the misuse of legitimate services and tools for malicious purposes, something that has been observed more and more frequently in recent years. What makes these attacks dangerous is not only the malware itself (such as AsyncRAT or RevengeRAT), but the combination of silent infiltration, persistent presence, and ease of bypassing security measures.

See also: Cloudflare announces OpenPubkey SSH

Addressing such threats now requires behavioral analysis, Zero Trust architecture , and continuous monitoring for suspicious activities, even when they come from "innocent" applications or well-known services.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS