Cloudflare Tunnels Abused in New Malware Campaign

Cloudflare Tunnels Abused in New Malware Campaign

Keypoints

  • The campaign uses phishing emails with PDF disguises and ZIP files to distribute malware.
  • Cloudflare tunnels enable attackers to host malicious payloads anonymously and evade detection.
  • The infection chain involves robocopy, obfuscated scripts, and Windows Script Host to execute payloads.
  • Malware includes shellcode loaders that deliver RATs like AsyncRAT and RevengeRAT in memory.
  • This campaign is part of a pattern of abuse of Cloudflare infrastructure for malware distribution.

Read More: https://www.securityweek.com/cloudflare-tunnels-abused-in-new-malware-campaign/