Cloudflare Tunnel subdomains are being used by a new campaign to host malicious payloads, which are then distributed through malicious attachments included in phishing emails.
Securonix has given the ongoing campaign the codename SERPENTINE#CLOUD. “The Cloudflare Tunnel infrastructure and Python-based loaders are utilized to deliver memory-injected payloads through a chain of shortcut files and obfuscated scripts,” according to a report that security researcher Tim Peck provided with The Hacker News.
Phishing emails with an invoice or payment theme and a link to a zipped document containing a Windows shortcut (LNK) file are the first step in the attack. By posing as papers, these shortcuts deceive victims into opening them, so starting the infection chain.
A Python-based shellcode loader that runs payloads loaded with the open-source Donut loader entirely in memory read more about New Malware Campaign Uses Cloudflare Tunnels to Deliver RATs via Phishing Chains.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
