“TryCloudflare” Abuse: AsyncRAT Exploits Free Tunnels to Build Stealthy WebDAV Network
ID: 6a6f8bae-75b8-51c0-abf4-4e6fa0ef0275
STIX ID: report--6a6f8bae-75b8-51c0-abf4-4e6fa0ef0275
Feed Name: securityonline.info
Trend Micro reports a sophisticated multi-stage campaign delivering the AsyncRAT remote access trojan by abusing Cloudflare free-tier services and TryCloudflare WebDAV hosting: victims receive phishing Dropbox links to ZIP files containing .url shortcuts that trigger downloads, a legitimate signed Python runtime is installed to execute ne.py which injects AsyncRAT into explorer.exe, and persistence is achieved via batch files placed in the Startup folder; the report warns that this living-off-the-land approach and cloud-tunneling abuse can bypass reputation checks and urges multi-layered defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
