New Malware Campaign Uses Cloudflare Tunnels to Deliver RATs via Phishing Chains
Cloudflare Tunnel subdomains are being used by a new campaign to host malicious payloads, which are then distributed through malicious attachments included in phishing emails.
Securonix has given the ongoing campaign the codename SERPENTINE#CLOUD. "The Cloudflare Tunnel infrastructure and Python-based loaders are utilized to deliver memory-injected payloads through a chain of shortcut files and obfuscated scripts," according to a report that security researcher Tim Peck provided with The Hacker News.
Phishing emails with an invoice or payment theme and a link to a zipped document containing a Windows shortcut (LNK) file are the first step in the attack. By posing as papers, these shortcuts deceive victims into opening them, so starting the infection chain.
A Python-based shellcod...

