AsyncRAT Abuses Cloudflare Free-Tier Services to Conceal Malicious Activity

Cybercriminals deploying AsyncRAT are exploiting Cloudflare’s free-tier services and TryCloudflare tunneling domains to host WebDAV servers, effectively masking their malicious operations behind trusted infrastructure.

This sophisticated technique makes detection highly challenging for traditional security solutions while ensuring reliable payload delivery to victim systems.

Attack Chain Overview

Threat map
Threat map

The campaign initiates with phishing emails containing Dropbox links that distribute files using double-extension techniques (.pdf.url) to deceive recipients.

When victims open these files, they download multi-stage scripts from TryCloudflare domains while simultaneously displaying legitimate PDF documents to avoid raising suspicion.

A particularly notable aspect of this campaign involves downloading legitimate Python distributions directly from official Python.org sources.

The attackers establish a complete Python environment on compromised systems, which they then use to execute advanced code injection techniques targeting the explorer.exe process.

Code Injection
Code Injection

The malware ensures long-term access through multiple persistence vectors. Attackers deploy startup folder scripts, including ahke.bat and olsm.bat files that execute automatically when users log into Windows.

The campaign also leverages WebDAV mounting capabilities to maintain connections with command-and-control infrastructure.

The threat actors employ “living-off-the-land” techniques extensively, utilizing built-in Windows utilities such as Windows Script Host, PowerShell, and native system tools.

This approach allows them to blend malicious activities with legitimate system operations, significantly complicating detection efforts.

Threat intelligence relationships
Threat intelligence relationships

By leveraging Cloudflare’s widely-trusted infrastructure, attackers successfully obscure malicious WebDAV servers behind legitimate-appearing domains containing “trycloudflare.com” in their URLs.

Security solutions often whitelist Cloudflare traffic, creating an effective blind spot that threat actors exploit to deliver AsyncRAT payloads undetected, as reported by Trend Micro.

The platform offers customers specialized threat hunting queries, detailed threat insights, and actionable intelligence reports to identify and respond to AsyncRAT infections, leveraging Cloudflare’s services.

Trend Micro research indicates the need to monitor WebDAV connections and assess traffic patterns involving TryCloudflare domains to detect potential misuse.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories