Hackers abuse free TryCloudflare to deliver remote access malware
ID: 06ebaa9e-e278-516f-8d96-8cd17ce4a6dc
STIX ID: report--06ebaa9e-e278-516f-8d96-8cd17ce4a6dc
Feed Name: Bleeping Computer
Researchers report a campaign abusing Cloudflare's free TryCloudflare Tunnel to host malicious .LNK payloads that droppowerShell/BAT loaders and ultimately install various RATs (AsyncRAT, GuLoader, VenomRAT, Remcos, Xworm). The attackers use tax-themed phishing emails and temporary trycloudflare.com subdomains to evade detection and have distributed at least 1,500 malicious messages in a recent wave, targeting organizations across law, finance, manufacturing, and technology sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
