logo

Threat Actors Abusing Cloudflare Workers Service To Deliver Weaponized Application

ID: 5117e833-0492-5776-a8d7-9f5a0ec99f75

STIX ID: report--5117e833-0492-5776-a8d7-9f5a0ec99f75

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2024-12-18

Date Updated: 2026-04-21

Author: Varshini Senapathi

...
...

CERT-UA reported a sophisticated campaign that abused Cloudflare Workers to host fake “Army+” download pages delivering an NSIS installer (e.g., ArmyPlusInstaller-*.exe) which unpacks a decoy .NET file, Python and Tor binaries, and a PowerShell script that installs OpenSSH, generates RSA keys, adds a public key to authorized_keys, exfiltrates the private key to a Tor address, and exposes a hidden SSH service—creating a covert remote access backdoor. The campaign is attributed to UAC-0125 (associated with APT44/Sandworm), highlighting an evolution in their tactics and an increased use of trusted platforms for malware distribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.