logo

A Cereal Offender: Analyzing the CORNFLAKE.V3 Backdoor

ID: e7044f73-8552-5996-b455-b7ffe6b22fec

STIX ID: report--e7044f73-8552-5996-b455-b7ffe6b22fec

Feed Name: Threat Intelligence

Threat Score
70/100

Date Published: 2025-08-20

Date Updated: 2026-04-27

Author: Mandiant

...
...

### Executive summary Since June 2024 Mandiant has tracked UNC5518 using fake CAPTCHA ("ClickFix") pages to deliver downloader scripts that provide access-as-a-service; those access points have been used by financially motivated UNC5774 to deploy CORNFLAKE.V3, a JavaScript/PHP backdoor that supports persistence, multiple payload types, and abuse of Cloudflare Tunnels to proxy command-and-control communications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.