Skip to main content

Hackers abuse free TryCloudflare to deliver remote access malware


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

August 1, 2024 By Bill Toulas

 

Hackers abuse free TryCloudflare to deliver remote access malware

Researchers are warning of threat actors increasingly abusing the Cloudflare Tunnel service in malware campaigns that usually deliver remote access trojans (RATs).

This cybercriminal activity was frst detected in February and it is leveraging the TryCloudflare free service to distribute multiple RATs, including AsyncRAT, GuLoader, VenomRAT, Remcos RAT, and Xworm.

Campaigns attributed to the same activity cluster
Campaigns attributed to the same activity cluster
Source: Proofpoint

The Cloudflare Tunnel service allows proxying traffic through an encrypted tunnel to access local services and servers over the internet without exposing IP addresses. This should come with added security and convenience because there is no need to open any public inbound ports or to set up VPN connections.

 

>>Full Article<<

0 replies

Be the first to reply!

Reply