PULSE NAME
Analyzing SERPENTINE#CLOUD: Threat Actors Abuse Cloudflare Tunnels to Infect Systems with Stealthy Python-Based Malware
WHITE AlienVault 2025-06-20 Modified: 2025-06-20
189
IOCs
HIGH VOLUME
The SERPENTINE#CLOUD campaign leverages Cloudflare Tunnels and Python-based loaders to deliver memory-injected payloads through a chain of shortcut files and obfuscated scripts. The attack begins with malicious .lnk files disguised as documents, fetching remote code from Cloudflare subdomains. The infection chain involves batch, VBScript, and Python stages, ultimately deploying shellcode that loads a Donut-packed PE payload. The campaign focuses on Western targets, using Cloudflare for payload hosting and anonymity. It demonstrates evolving tactics, shifting from simple .url files to sophisticated .lnk payloads. The final stage involves a RAT payload, giving attackers full control over infected hosts.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
AsyncRAT RevengeRAT
Indicators of Compromise (19 / 189 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 8e9d18b754aaf7aadb3bd2c20ab9f4aee409b73d 2025-06-20
FileHash-SHA1 037736cf63cf047f5165f0b6e0ab1d86d3d96512 2025-06-20
FileHash-SHA1 03e875c55f3b1c95dd7f0a370d1fc0a3d043b688 2025-06-20
FileHash-SHA1 27752e008f1aaa83b0b09f82632f47aeb05f51d9 2025-06-20
FileHash-SHA1 38fab408803fbe65079b66cb5ecbf6686efe9353 2025-06-20
FileHash-SHA1 76bdb98ac85ceca629357c469606eabf3f9ad49c 2025-06-20
FileHash-SHA1 80c83fcd717bd03fa463a75684c5541fce9fff55 2025-06-20
FileHash-SHA1 8f1f544c57b26784e0d191c9678067a505b4f339 2025-06-20
FileHash-SHA1 965d653fee4acd9c3fa7258096782d9ee3246916 2025-06-20
FileHash-SHA1 a375e27ec85dd7b04ce44d4c02a0e5e162e484f0 2025-06-20
FileHash-SHA1 a4265b36ecc13e1c4ecd9a1eb33727cdb3354a45 2025-06-20
FileHash-SHA1 ae271809c8f2bd86db95199dcf7081b42e7f61f5 2025-06-20
FileHash-SHA1 c1c2e51f52552c8a1e23d31d8d57662acb9bf6de 2025-06-20
FileHash-SHA1 c735c2d22e2fe79a39111e76a9966d0720f023a1 2025-06-20
FileHash-SHA1 e0553dba46dba677e8b509acc7076ee8cf75b5f8 2025-06-20
FileHash-SHA1 e05ea2ddb8df7cd9006d3b3114270093356ac161 2025-06-20
FileHash-SHA1 f08195863426c9dae4f1fc89014e9ae49ae576fd 2025-06-20
FileHash-SHA1 f6698a92f659dbae256a4726bd52c1e934d9cdce 2025-06-20
FileHash-SHA1 fca3dc54787f1a9dd44750f12da4b25563db85e7 2025-06-20