Russian-Speaking Threat Actor Abuses Cloudflare & Telegram in Phishing Campaign
ID: e0c5612b-f4ff-59b6-802b-39fb46c0fab8
STIX ID: report--e0c5612b-f4ff-59b6-802b-39fb46c0fab8
Feed Name: Hunt.io Blog
Hunt.io researchers observed a new wave of attacks by a Russian‑speaking operator using Cloudflare Pages/Workers phishing pages (DMCA-themed) that invoke the search-ms protocol to fetch a malicious LNK (disguised as a PDF). Execution of the LNK runs a PowerShell loader (kozlina2.ps1) which downloads a ZIP containing python.exe and a Python loader (kursor.py) that establishes persistence and communicates with Pyramid C2; the PowerShell script also reports infected hosts' external IPs to a hardcoded Telegram bot. The report documents the abused infrastructure (open directories on Railnet IPs, numerous workers.dev/pages.dev domains), file hashes, IPs, and behavioral details to support detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
