Threat Actors Abusing Cloudflare Workers Service To Deliver Weaponized Application
ID: 5117e833-0492-5776-a8d7-9f5a0ec99f75
STIX ID: report--5117e833-0492-5776-a8d7-9f5a0ec99f75
Feed Name: cybersecurityNews.com
CERT-UA reported a sophisticated campaign that abused Cloudflare Workers to host fake “Army+” download pages delivering an NSIS installer (e.g., ArmyPlusInstaller-*.exe) which unpacks a decoy .NET file, Python and Tor binaries, and a PowerShell script that installs OpenSSH, generates RSA keys, adds a public key to authorized_keys, exfiltrates the private key to a Tor address, and exposes a hidden SSH service—creating a covert remote access backdoor. The campaign is attributed to UAC-0125 (associated with APT44/Sandworm), highlighting an evolution in their tactics and an increased use of trusted platforms for malware distribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
