Serpentine#Cloud Uses Cloudflare Tunnels in Sneak Attacks
ID: 68d83fec-f4be-5dc8-924e-85a600c7cad8
STIX ID: report--68d83fec-f4be-5dc8-924e-85a600c7cad8
Feed Name: Dark Reading
Date Published: 2025-06-18
Date Updated: 2026-04-21
Author: Alexander Culafi, Senior News Writer, Dark Reading
Securonix researchers describe an active, sophisticated campaign called "Serpentine#Cloud" in which phished .lnk shortcut files fetch obfuscated batch scripts that deploy decoy documents, check antivirus, and ultimately load Python-based in-memory shellcode hosted via Cloudflare's trycloudflare.com tunnels, resulting in backdoored systems across multiple countries; attribution is currently unknown and defenders are advised to focus on endpoint detection and phishing hygiene.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
