Sunday , August 2 2026
flowchart

Hackers Abuses Cloudflare Tunnels to Deliver malware

Proofpoint is monitoring a group of cybercriminals using Cloudflare Tunnels to distribute malware. They are exploiting the TryCloudflare feature to create one-time tunnels without needing an account. Tunnels allow remote access to data and resources not on the local network, similar to using a virtual private network (VPN) or secure shell (SSH) protocol.

   Malware observed in related campaigns leveraging “trycloudflare” tunnels.

In February 2024, a cluster was first seen. From May to July, there was an increase in activity. Most of the campaigns resulted in Xworm, a remote access trojan (RAT), in the past few months.

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
CISA alerts to cyberattacks affecting U.S. water utilities

“CyberStrike” AI-Driven Security Platform for Automated Testing

A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
“CyberStrike” AI-Driven Security Platform for Automated Testing

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

Campaign messages often include a URL or attachment that leads to an internet shortcut (.URL) file. This file connects to an external file share when opened, allowing the download of malicious files. These files can lead to the installation of malware on the user’s system. In some cases, a benign PDF file is shown to the user to look trustworthy.

Most campaigns in June and July delivered a malware called Xworm. However, previous campaigns delivered other malwares like AsyncRAT, VenomRAT, GuLoader, and Remcos. Some campaigns even lead to the installation of multiple malwares, with each unique Python script installing a different one.

Campaign messages can range from hundreds to tens of thousands, affecting many organizations worldwide. Besides English, researchers found lures in French, Spanish, and German. Xworm, AsyncRAT, and VenomRAT campaigns are usually larger than Remcos or GuLoader campaigns. Lure topics vary, but often relate to business, like invoices, document requests, package deliveries, and taxes.

    28 May 2024 attack chain

The threat actor modifies different parts of the attack chain to become more sophisticated and avoid defense. Initially, their scripts had no obfuscation and included detailed comments. However, in June, they started to use obfuscation in their code.

Cybercriminals are increasingly using TryCloudflare tunnels to create random subdomains on trycloudflare.com, such as ride-fatal-italic-information.trycloudflare.com, to proxy traffic to their local servers. Full report here.

Check Also

CVE-2026-20230

Cisco Unified CM flaw CVE-2026-20230 exploited in attacks

A serious SSRF flaw, called CVE-2026-20230, in Cisco Unified Communications Manager Server is now being …