The Unintentional Enabler: How Cloudflare Services are Abused for Credential Theft and Malware Distribution
ID: 5d0ee297-1862-5de3-a3fb-265ca41d6c65
STIX ID: report--5d0ee297-1862-5de3-a3fb-265ca41d6c65
Feed Name: Cofense Blog
Cofense Intelligence describes a growing campaign trend in which attackers abuse Cloudflare services—especially Workers and TryCloudflare Tunnels—to host convincing AiTM and credential-phishing pages and to deliver malware (e.g., Xeno RAT, XWorm) via URL shortcuts, WSF/batch chains and WebDAV. These tactics leverage Cloudflare’s reputation, free tiers, and tunneling to evade SEGs and sandboxing, enabling fast campaign rotation, persistent remote access, and broad impact; the report includes examples, IOCs, and recommendations for intelligence-driven defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
