logo

Russian-Speaking Threat Actor Abuses Cloudflare & Telegram in Phishing Campaign

ID: e0c5612b-f4ff-59b6-802b-39fb46c0fab8

STIX ID: report--e0c5612b-f4ff-59b6-802b-39fb46c0fab8

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

Hunt.io researchers observed a new wave of attacks by a Russian‑speaking operator using Cloudflare Pages/Workers phishing pages (DMCA-themed) that invoke the search-ms protocol to fetch a malicious LNK (disguised as a PDF). Execution of the LNK runs a PowerShell loader (kozlina2.ps1) which downloads a ZIP containing python.exe and a Python loader (kursor.py) that establishes persistence and communicates with Pyramid C2; the PowerShell script also reports infected hosts' external IPs to a hardcoded Telegram bot. The report documents the abused infrastructure (open directories on Railnet IPs, numerous workers.dev/pages.dev domains), file hashes, IPs, and behavioral details to support detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.