BlueAlpha Abuses Cloudflare Tunneling Service for GammaDrop Staging Infrastructure
ID: 677fec2d-f342-5c39-ad44-6660382124dd
STIX ID: report--677fec2d-f342-5c39-ad44-6660382124dd
Feed Name: Recorded Future Blog
BlueAlpha, an FSB-directed APT active since at least 2014, has been delivering custom malware (GammaDrop dropper and GammaLoad loader) against Ukrainian organizations; the group now abuses Cloudflare Tunnels (trycloudflare.com subdomains) and HTML smuggling to stage and deliver payloads while using DNS fast-flux and heavy obfuscation to evade detection, enabling credential theft, data exfiltration, and persistent access—organizations are advised to harden email defenses, restrict risky execution paths (e.g., mshta.exe), monitor trycloudflare subdomains and DoH traffic, and apply threat intelligence countermeasures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
