Securonix has identified a malware distribution campaign called Serpentine#Cloud that exploits Cloudflare Tunnels for payload delivery using phishing emails and obfuscated scripts. The campaign employs advanced infection methods, including Python loaders and RATs like AsyncRAT and RevengeRAT, to maintain persistence and stealth. #CloudflareTunnel #SerpentineCloud #AsyncRAT #RevengeRAT
Keypoints
- The campaign uses phishing emails with PDF disguises and ZIP files to distribute malware.
- Cloudflare tunnels enable attackers to host malicious payloads anonymously and evade detection.
- The infection chain involves robocopy, obfuscated scripts, and Windows Script Host to execute payloads.
- Malware includes shellcode loaders that deliver RATs like AsyncRAT and RevengeRAT in memory.
- This campaign is part of a pattern of abuse of Cloudflare infrastructure for malware distribution.
Read More: https://www.securityweek.com/cloudflare-tunnels-abused-in-new-malware-campaign/