logo

Attackers Abuse Python, Cloudflare to Deliver AsyncRAT

ID: f9e51728-a424-52a5-b075-8a88a200099d

STIX ID: report--f9e51728-a424-52a5-b075-8a88a200099d

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2026-01-13

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Trend Micro researchers uncovered a phishing campaign that leverages Cloudflare free-tier services and TryCloudflare tunneling domains to host multi-stage scripts which install a Python environment, perform code injection into explorer.exe, and deliver AsyncRAT; attackers use invoice-themed lures, double-extension (.pdfurl) archives, and living-off-the-land persistence techniques, with IoCs and mitigation guidance provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.