logo

Government Hit by Multi-Malware Cyberattack via Cloudflare Service

ID: ba0b2a78-e33c-55a4-8225-1a07448f22e2

STIX ID: report--ba0b2a78-e33c-55a4-8225-1a07448f22e2

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2024-08-06

Date Updated: 2026-04-22

Author: do son

...
...

eSentire TRU uncovered a phishing-based campaign against government targets that used a TryCloudflare-proxied WebDAV server to distribute encrypted and highly obfuscated payloads (obfuscated .bat and Python files) which deployed XWorm, AsyncRAT, VenomRAT and PureLogs Stealer; the attack chain employed in-memory shellcode (Donut loader), direct syscalls and Early Bird APC injection to evade EDR and achieve persistence and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.