logo

“TryCloudflare” Abuse: AsyncRAT Exploits Free Tunnels to Build Stealthy WebDAV Network

ID: 6a6f8bae-75b8-51c0-abf4-4e6fa0ef0275

STIX ID: report--6a6f8bae-75b8-51c0-abf4-4e6fa0ef0275

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-13

Date Updated: 2026-04-23

Author: Ddos

...
...

Trend Micro reports a sophisticated multi-stage campaign delivering the AsyncRAT remote access trojan by abusing Cloudflare free-tier services and TryCloudflare WebDAV hosting: victims receive phishing Dropbox links to ZIP files containing .url shortcuts that trigger downloads, a legitimate signed Python runtime is installed to execute ne.py which injects AsyncRAT into explorer.exe, and persistence is achieved via batch files placed in the Startup folder; the report warns that this living-off-the-land approach and cloud-tunneling abuse can bypass reputation checks and urges multi-layered defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.