Attackers Abuse Python, Cloudflare to Deliver AsyncRAT
ID: f9e51728-a424-52a5-b075-8a88a200099d
STIX ID: report--f9e51728-a424-52a5-b075-8a88a200099d
Feed Name: Dark Reading
Date Published: 2026-01-13
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Trend Micro researchers uncovered a phishing campaign that leverages Cloudflare free-tier services and TryCloudflare tunneling domains to host multi-stage scripts which install a Python environment, perform code injection into explorer.exe, and deliver AsyncRAT; attackers use invoice-themed lures, double-extension (.pdfurl) archives, and living-off-the-land persistence techniques, with IoCs and mitigation guidance provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
