logo

BlueAlpha Abuses Cloudflare Tunneling Service for GammaDrop Staging Infrastructure

ID: 677fec2d-f342-5c39-ad44-6660382124dd

STIX ID: report--677fec2d-f342-5c39-ad44-6660382124dd

Feed Name: Recorded Future Blog

Threat Score
85/100

Date Published: 2024-12-05

Date Updated: 2026-04-28

...
...

BlueAlpha, an FSB-directed APT active since at least 2014, has been delivering custom malware (GammaDrop dropper and GammaLoad loader) against Ukrainian organizations; the group now abuses Cloudflare Tunnels (trycloudflare.com subdomains) and HTML smuggling to stage and deliver payloads while using DNS fast-flux and heavy obfuscation to evade detection, enabling credential theft, data exfiltration, and persistent access—organizations are advised to harden email defenses, restrict risky execution paths (e.g., mshta.exe), monitor trycloudflare subdomains and DoH traffic, and apply threat intelligence countermeasures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.