Russia's 'BlueAlpha' APT Hides in Cloudflare Tunnels
ID: 6c49a542-33c8-539a-8ccc-e16c228326c0
STIX ID: report--6c49a542-33c8-539a-8ccc-e16c228326c0
Feed Name: Dark Reading
Date Published: 2024-12-05
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
Recorded Future’s Insikt Group reports that the Russian state-sponsored APT BlueAlpha is abusing Cloudflare Tunnels (TryCloudflare subdomains) to hide staging infrastructure and deliver its proprietary GammaDrop malware using HTML smuggling and DNS fast-flux; GammaDrop enables data exfiltration, credential theft, and backdoor access, and the group has targeted Ukrainian organizations with spearphishing and custom VBScript malware (GammaLoad). Insikt recommends strengthening email defenses against HTML smuggling, flagging suspicious HTML attachments and trycloudflare.com requests, and blocking misuse of mshta.exe and untrusted .lnk files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
