Hackers Leveraging Cloudflare Tunnels DNS Fast-Flux to Hide GammaDrop Malware

Cloudflare Tunnels have been used by the threat actor Gamaredon to hide its staging infrastructure, which is home to the malware GammaDrop.

According to a new investigation by Recorded Future’s Insikt Group, the activity is a part of a spear-phishing effort that has been targeting Ukrainian companies since at least early 2024 with the goal of releasing the Visual Basic Script virus.

Under the alias BlueAlpha—also known as Aqua Blizzard, Armageddon, Hive0051, Iron Tilden, Primitive Bear, Shuckworm, Trident Ursa, UAC-0010, UNC530, and Winterflounder—the cybersecurity firm is monitoring the threat actor. The group is associated with Russia’s Federal Security Service (FSB) and is thought to have been operating since 2014 read more about Hackers Leveraging Cloudflare Tunnels DNS Fast-Flux to Hide GammaDrop Malware.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *