logo

The Unintentional Enabler: How Cloudflare Services are Abused for Credential Theft and Malware Distribution

ID: 5d0ee297-1862-5de3-a3fb-265ca41d6c65

STIX ID: report--5d0ee297-1862-5de3-a3fb-265ca41d6c65

Feed Name: Cofense Blog

Threat Score
75/100

Date Published: 2026-03-25

Date Updated: 2026-04-27

Author: Cofense

...
...

Cofense Intelligence describes a growing campaign trend in which attackers abuse Cloudflare services—especially Workers and TryCloudflare Tunnels—to host convincing AiTM and credential-phishing pages and to deliver malware (e.g., Xeno RAT, XWorm) via URL shortcuts, WSF/batch chains and WebDAV. These tactics leverage Cloudflare’s reputation, free tiers, and tunneling to evade SEGs and sandboxing, enabling fast campaign rotation, persistent remote access, and broad impact; the report includes examples, IOCs, and recommendations for intelligence-driven defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.