logo

AsyncRAT Leveraging Cloudflare’s Free-Tier Services to Mask Malicious Activities and Detection

ID: dba452ff-2903-54ab-9fef-c7ca332fec5f

STIX ID: report--dba452ff-2903-54ab-9fef-c7ca332fec5f

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-13

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A multi-stage AsyncRAT campaign leverages Dropbox-hosted invoice-themed ZIPs containing deceptive .url shortcuts that connect to WebDAV resources on TryCloudflare/Cloudflare-backed domains. Stages include downloading batch and PowerShell scripts, installing an embedded Python 3.14 runtime into a user folder, creating Startup persistence (ahke.bat, olsm.bat) to run a Python loader (ne.py), and performing polymorphic APC-based code injection into explorer.exe using encrypted shellcode (new.bin) and keys (a.txt). Trend Micro telemetry links multiple TryCloudflare domains to the same backend and provides commands, filenames, and domains observed, highlighting how attackers blend into legitimate cloud traffic and official Python downloads to evade simple reputation-based defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.