logo

Hackers abuse free TryCloudflare to deliver remote access malware

ID: 06ebaa9e-e278-516f-8d96-8cd17ce4a6dc

STIX ID: report--06ebaa9e-e278-516f-8d96-8cd17ce4a6dc

Feed Name: Bleeping Computer

Threat Score
68/100

Date Published: 2024-08-01

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Researchers report a campaign abusing Cloudflare's free TryCloudflare Tunnel to host malicious .LNK payloads that droppowerShell/BAT loaders and ultimately install various RATs (AsyncRAT, GuLoader, VenomRAT, Remcos, Xworm). The attackers use tax-themed phishing emails and temporary trycloudflare.com subdomains to evade detection and have distributed at least 1,500 malicious messages in a recent wave, targeting organizations across law, finance, manufacturing, and technology sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.