Threats Tagged 'cloudflare'
View all threats tagged with 'cloudflare'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cloudflare'
Click on any threat for detailed analysis and mitigation recommendations
AvisLoader is a newly discovered Windows malware loader that uses the Tox encrypted peer-to-peer messaging network for command-and-control communications, making traditional domain-based takedowns ineffective. The infection begins with a ClickFix social engineering technique, where victims are tricked into copying and executing malicious commands disguised as document verification steps. The loader is delivered through Cloudflare infrastructure and includes various stealth capabilities such as shortcut modification for persistence, UAC bypass attempts via UACME method 41, and process-hiding functionality through API hooking. Operators manage infected systems through a web-based Command Center that enables client management, task configuration, and payload distribution over the Tox network. The malware's architecture allows operators to maintain control by simply copying their Tox save file when relocating infrastructure, with clients automatically following without requiring domain updates. Join the discussion | AlienVault OTX General | 09/23/2026, 17:33:28 UTC Added: 09/23/2026, 20:02:51 UTC |
This threat involves a sophisticated malware infection chain that uses PowerShell loaders to deliver encrypted NetSupport Manager payloads hidden inside fake MP4 files. These MP4 files appear legitimate to basic file-type checks but contain encrypted data in ISO Base Media File Format uuid extension boxes instead of actual video content. The attack starts with PowerShell scripts delivered via Cloudflare-fronted infrastructure, which perform environment checks before retrieving the malicious carrier file. A secondary script extracts and decrypts a large embedded PowerShell payload that silently installs NetSupport Manager, a remote administration tool. The infrastructure includes multiple live endpoints across several autonomous systems, primarily located in Frankfurt and Los Angeles, with command-and-control gateways registered in rapid succession. The attackers use Russian-language business site decoys and frequently rotate carrier files without backward compatibility. Join the discussion | AlienVault OTX General | 08/29/2026, 00:24:24 UTC Added: 08/31/2026, 09:52:14 UTC |
Between June 16 and 19, 2026, a sophisticated adversary-in-the-middle phishing campaign targeted AWS console users through three domains registered within 48 hours and hosted on Cloudflare. The campaign impersonated AWS login pages and captured credentials along with real-time multi-factor authentication codes through email, SMS, and authenticator apps. Phishing emails were delivered through legitimate platforms like SendGrid and Nimbu to bypass spam filters. The kit employed JavaScript-based credential harvesting with victim validation through encrypted URL parameters, preventing sandbox analysis. Targets were primarily US-based software engineers and engineering leadership, suggesting a curated target list rather than mass phishing. The same kit was linked to concurrent SendGrid impersonation campaigns and previous cryptocurrency wallet targeting since July 2025. The small sample of fewer than 50 targeted email addresses indicates highly selective targeting of technical personnel with AWS access. Join the discussion | AlienVault OTX General | 06/25/2026, 15:26:35 UTC Added: 06/25/2026, 15:46:12 UTC |
IOCs related to FlowerStorm phishing‑kit–driven campaign that delivers fake Microsoft authentication pages via compromised domains fronted by Cloudflare. The activity abuses legitimate cloud and CDN services for delivery while credential harvesting occurs on attacker‑controlled infrastructure, with incidental contact to Microsoft services during normal browser behavior.that uses its own web servers to target victims' login credentials and access to their personal details and login details on its servers. Join the discussion | AlienVault OTX General | 04/20/2026, 13:20:34 UTC Added: 04/20/2026, 13:46:05 UTC |
The Warlock ransomware group has enhanced its attack chain with improved methods for persistence, lateral movement, and evasion. Their updated toolset includes TightVNC, Yuze, and a persistent BYOVD technique exploiting the NSec driver. The group's primary targets were technology, manufacturing, and government sectors, with the US, Germany, and Russia being the most affected countries. Warlock continues to exploit unpatched Microsoft SharePoint servers for initial access, and has expanded its post-exploitation toolkit. New additions include TightVNC for persistent remote access, Yuze for establishing SOCKS5 connections, and a BYOVD technique using the NSecKrnl.sys driver to terminate security products. The group also leverages Velociraptor, VS Code tunnels, and Cloudflare Tunnel for C&C communications. Join the discussion | AlienVault OTX General | 03/16/2026, 11:01:03 UTC Added: 03/16/2026, 18:57:30 UTC |
Threat actors exploited Cloudflare's free-tier infrastructure and Python environments to deploy AsyncRAT, demonstrating advanced evasion techniques. The attack begins with phishing emails containing Dropbox links to malicious files. It uses legitimate Python downloads and sophisticated code injection targeting explorer.exe. The campaign ensures persistence through multiple vectors, including startup folder scripts and WebDAV mounting. It abuses trusted infrastructure like Cloudflare to mask activities and evade detection. The attackers employ social engineering tactics, such as displaying legitimate PDF documents, to reduce suspicion. This campaign highlights the trend of abusing cloud services for malware delivery and execution, emphasizing the need for multi-layered security approaches. Join the discussion | AlienVault OTX General | 01/12/2026, 20:30:28 UTC Added: 01/13/2026, 16:11:30 UTC |
Showing 1 to 6 of 6 results