logo

AsyncRAT Campaign Abuses TryCloudflare Tunnels and Python Scripts for Malware Delivery

ID: b8084cb3-978c-5c48-aa25-6fffca5b6f33

STIX ID: report--b8084cb3-978c-5c48-aa25-6fffca5b6f33

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-07-02

Date Updated: 2026-07-03

Author: Tushar Subhra Dutta

...
...

Forcepoint researchers tracked a phishing-driven AsyncRAT campaign that hides payload delivery behind Dropbox links and TryCloudflare tunnels; a multi-stage chain downloads a malicious Python package whose loader uses Early Bird APC injection to deploy AsyncRAT, VenomRAT, or XWorm. The report provides IoCs (URLs, C2 IPs, and file hashes), describes detection coverage and mitigation recommendations, and warns that abuse of trusted infrastructure will continue to aid evasive malware campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.