Cybercriminals are increasingly exploiting the TryCloudflare Tunnel to deploy Remote Access Trojans (RATs) in financially motivated attacks. The TryCloudflare feature allows developers to test Cloudflare Tunnel without integrating a site into Cloudflare’s DNS.
Threat actors are constantly evolving their methods to evade detection and improve the effectiveness of their campaigns, making it harder to attribute their activities and requiring continuous analysis. They use TryCloudflare’s temporary infrastructure to distribute malware, particularly Xworm RAT, by leveraging the service’s fleeting nature to avoid conventional security measures.
This trend, which began in February 2024, has grown in intensity, posing a significant risk due to its rapid deployment and ability to bypass security defenses. Recent attacks have involved malware delivered through URLs or attachments, with tactics including the use of internet shortcuts to download LNK or VBS files from WebDAV shares. These files then execute BAT or CMD scripts to download and install malware like Xworm, AsyncRAT, VenomRAT, GuLoader, or Remcos.
Some of these campaigns use search-ms protocol handlers for LNK file retrieval and disguise malicious activities within seemingly harmless PDFs. While Xworm is the predominant threat, the adaptable delivery method means that a variety of malware payloads can be deployed, with different Python scripts potentially installing distinct threats.
A particular threat actor is running extensive email campaigns targeting global organizations with messages in various languages, delivering multiple RATs including Xworm, AsyncRAT, and VenomRAT. These campaigns often surpass the volume of Remcos and GuLoader-related attacks.
Despite using consistent tactics, the attacker frequently updates the attack chain, including recent efforts to obscure helper scripts to avoid detection and enhance operational security, highlighting the sophistication and persistence of the threat.
Cybercriminals are increasingly misusing TryCloudflare tunnels to set up malicious infrastructure. They create random subdomains on trycloudflare.com, routing traffic through Cloudflare to their local servers, which helps them bypass traditional security controls and complicates threat detection.
On May 28, 2024, a targeted email campaign used tax-themed lures to distribute AsyncRAT and Xworm malware to law and finance firms. The emails contained URLs leading to zipped files, which then directed to remote LNK files. Executing these files triggered a PowerShell script that downloaded a Python package and scripts, installing AsyncRAT and Xworm and granting the attackers remote access and data exfiltration capabilities.
According to Proofpoint, on July 11, 2024, another cyberattack campaign targeted the finance, manufacturing, and technology sectors using Cloudflare tunnels to spread AsyncRAT and Xworm. More than 1,500 emails, disguised as order invoices, included HTML attachments with search-ms queries pointing to malicious LNK files. Executing these LNK files launched an obfuscated BAT script that downloaded a Python installer, ultimately installing AsyncRAT and Xworm via PowerShell.



