logo

Sneaky Serpentine#Cloud slithers through Cloudflare tunnels to inject orgs with Python-based malware

ID: 8e91f0a3-e89b-5f85-b029-cbd4411822d2

STIX ID: report--8e91f0a3-e89b-5f85-b029-cbd4411822d2

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2025-06-19

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Serpentine#Cloud is an active, medium-to-large-scale malware campaign that uses invoice-themed phishing (.lnk files) and Cloudflare TryCloudflare tunnels to stealthily deliver multi-stage loaders (batch, VBScript, Python) which execute Donut-packed in-memory RATs (AsyncRAT/Revenge RAT). The attackers leverage WebDAV over HTTPS, TLS-backed Cloudflare infrastructure, and startup persistence to evade detection and maintain long-term access; infections have been observed across multiple Western countries and in Asia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.