logo

Hackers Abuse Cloudflare Storage to Exfiltrate Network Files

ID: 2d2ae2d7-1c53-5f10-863e-27f5136df538

STIX ID: report--2d2ae2d7-1c53-5f10-863e-27f5136df538

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-05-18

Date Updated: 2026-05-19

Author: Mayura Kathir

...
...

A targeted cyber-espionage campaign against Malaysian organisations leveraged an Azure VM to host attacker tooling (custom Python scripts, Laravel exploit chains, a C# beacon and Python C2 listener, and a PHP webshell), used Cloudflare-hosted storage for stealthy exfiltration, and achieved at least one full domain compromise with exfiltrated SAM/NTDS/registry hives—enabling credential harvesting, lateral movement, and persistent access; organizations should remove webshells, rotate domain credentials, and perform deep forensics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.