Skip to main content

Threats Tagged 'cloudflare workers'

View all threats tagged with 'cloudflare workers'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cloudflare workers

Threats Tagged 'cloudflare workers'

Click on any threat for detailed analysis and mitigation recommendations

A coordinated campaign involving 77 Firefox browser extensions has been identified, targeting cryptocurrency users by stealing wallet secrets and credentials. The campaign, named 'Offside Wallet Theft Factory,' includes 40 confirmed malicious extensions that exfiltrate sensitive data such as recovery phrases and private keys using Supabase-controlled remote switches, Cloudflare Workers, and hardcoded command-and-control infrastructure. An additional 37 extensions initially appeared benign but evolved into wallet-stealing malware. The operation ran from at least March 2026 through August 2026, impersonating popular Web3 products like OKX, Rabby Wallet, and TronLink. The extensions employ phishing interfaces, modified wallet code, and direct credential theft to enable immediate cryptocurrency theft and financial loss.

Join the discussion

A China-nexus threat actor is targeting Myanmar government personnel and diplomats through Operation QUICSILVER, delivering malware via Virtual Hard Disk files disguised as JPEG images. The campaign uses Burmese-language lures impersonating Myanmar's Information Technology and Cyber Security Department, including graduation ceremony invitations. The multi-stage infection chain begins with a malicious LNK file that abuses ftp.exe to execute scripts, reconstructs payloads from split files, and deploys QUICAgent, a custom Go-based backdoor. The implant retrieves C2 infrastructure through Cloudflare Workers, communicates over HTTP/3 using QUIC protocol, and employs RC4 encryption. Deleted documents recovered from the VHD reveal interest in ASEAN affairs, BIMSTEC, and Myanmar diplomatic activities. Three related campaigns were identified between April and July 2026, sharing similar TTPs and infrastructure.

Join the discussion

Recent investigations have uncovered sophisticated phishing campaigns employing multi-stage redirection chains that abuse trusted cloud infrastructure and newly registered domains. One campaign exploits Framer, a no-code web platform, combined with Cloudflare Workers to host deceptive landing pages. These pages utilize HTML redirection smuggling via the Blob API, Web Crypto API for decryption, and anti-debugging techniques to evade detection. Another campaign involves device code phishing targeting OneDrive credentials through three-stage redirections using newly registered domains with randomized alphanumeric strings. Both campaigns employ brand impersonation, custom CAPTCHA challenges, and anti-analysis measures including keyboard shortcut blocking. The threat actors leverage a hybrid infrastructure combining legitimate cloud services with short-lived domains to bypass traditional detection methods.

Join the discussion

A widespread phishing campaign distributing AsyncRAT and Remcos RATs has been observed targeting organizations across manufacturing, media, professional services, agriculture, and chemical industries globally. The attack leverages malicious Excel spreadsheets sent via emails impersonating business communications like purchase orders and payment advice. When macros are enabled, VBA code retrieves HTA payloads through URL shorteners and Cloudflare Workers infrastructure. The multi-stage infection chain employs heavy obfuscation including Base64 encoding, steganography in PNG files, and character substitution. The campaign intensified during June 2026, affecting organizations across Europe, Asia-Pacific, and the Americas. Infrastructure includes distinctive HTA naming conventions using concatenated positive English words. The operation likely uses automation for payload generation and may leverage LLMs for development efficiency.

Join the discussion

An extensive cyber espionage campaign conducted by SloppyLemming, an India-nexus threat actor, targeted government entities and critical infrastructure in Pakistan and Bangladesh from January 2025 to January 2026. The campaign used two attack vectors: PDF lures with ClickOnce execution chains and macro-enabled Excel documents. It deployed a custom x64 shellcode implant named BurrowShell and a Rust-based keylogger. The attackers extensively abused Cloudflare Workers for C2 and payload delivery, registering 112 domains impersonating government entities. The campaign focused on nuclear, defense, telecommunications, energy, and financial sectors, aligning with regional strategic competition in South Asia.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Tag: cloudflare workers
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses