cognitive cybersecurity intelligence

News and Analysis

Search

Hackers Exploit Cloudflare Tunnel Infrastructure to Deploy Multiple Remote Access Trojans

Hackers Exploit Cloudflare Tunnel Infrastructure to Deploy Multiple Remote Access Trojans

The Sekoia TDR team detected a sophisticated cyber attack infrastructure named “Cloudflare tunnel infrastructure,” used to deliver remote access trojans, including AsyncRAT, since February 2024. Initiated through a phishing email, the complex multi-step process begins by opening an “application/windows-library+xml” attachment. This activates a connection to a WebDAV resource within Cloudflare, leading to the execution of a deceptive LNK file, evasion of defenses, and persistent malware through the Windows Startup folder.

Source: gbhackers.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts