Sneaky Serpentine#Cloud slithers through Cloudflare tunnels to inject orgs with Python-based malware
ID: 8e91f0a3-e89b-5f85-b029-cbd4411822d2
STIX ID: report--8e91f0a3-e89b-5f85-b029-cbd4411822d2
Feed Name: The Register (Security)
Serpentine#Cloud is an active, medium-to-large-scale malware campaign that uses invoice-themed phishing (.lnk files) and Cloudflare TryCloudflare tunnels to stealthily deliver multi-stage loaders (batch, VBScript, Python) which execute Donut-packed in-memory RATs (AsyncRAT/Revenge RAT). The attackers leverage WebDAV over HTTPS, TLS-backed Cloudflare infrastructure, and startup persistence to evade detection and maintain long-term access; infections have been observed across multiple Western countries and in Asia.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
