Cybercriminals deploying AsyncRAT are exploiting Cloudflare’s free-tier services and TryCloudflare tunneling domains to host WebDAV servers, effectively masking their malicious operations behind trusted infrastructure.
This sophisticated technique makes detection highly challenging for traditional security solutions while ensuring reliable payload delivery to victim systems.
Attack Chain Overview

The campaign initiates with phishing emails containing Dropbox links that distribute files using double-extension techniques (.pdf.url) to deceive recipients.
When victims open these files, they download multi-stage scripts from TryCloudflare domains while simultaneously displaying legitimate PDF documents to avoid raising suspicion.
A particularly notable aspect of this campaign involves downloading legitimate Python distributions directly from official Python.org sources.
The attackers establish a complete Python environment on compromised systems, which they then use to execute advanced code injection techniques targeting the explorer.exe process.

The malware ensures long-term access through multiple persistence vectors. Attackers deploy startup folder scripts, including ahke.bat and olsm.bat files that execute automatically when users log into Windows.
The campaign also leverages WebDAV mounting capabilities to maintain connections with command-and-control infrastructure.
The threat actors employ “living-off-the-land” techniques extensively, utilizing built-in Windows utilities such as Windows Script Host, PowerShell, and native system tools.
This approach allows them to blend malicious activities with legitimate system operations, significantly complicating detection efforts.

By leveraging Cloudflare’s widely-trusted infrastructure, attackers successfully obscure malicious WebDAV servers behind legitimate-appearing domains containing “trycloudflare.com” in their URLs.
Security solutions often whitelist Cloudflare traffic, creating an effective blind spot that threat actors exploit to deliver AsyncRAT payloads undetected, as reported by Trend Micro.
The platform offers customers specialized threat hunting queries, detailed threat insights, and actionable intelligence reports to identify and respond to AsyncRAT infections, leveraging Cloudflare’s services.
Trend Micro research indicates the need to monitor WebDAV connections and assess traffic patterns involving TryCloudflare domains to detect potential misuse.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.