HomeNewsRussian hackers abuse Cloudflare tunneling service to drop GammaDrop malware

Russian hackers abuse Cloudflare tunneling service to drop GammaDrop malware

In a brand new marketing campaign, a Russia-backed superior persistent risk (APT) group is seen abusing Cloudflare tunnels to ship its proprietary GammaLoad malware.

The risk actor, tracked as BlueAlpha, was noticed by the cybersecurity analysis agency Insikt Group to be exploiting this professional tunneling service for infections aimed toward knowledge exfiltration, credential theft, and protracted entry to compromised networks.

“BlueAlpha makes use of Cloudflare Tunnels to hide its GammaDrop staging infrastructure, evading conventional community detection mechanisms,” researchers at Insikt stated in a word. “The group delivers malware by means of HTML smuggling, leveraging refined methods to bypass e-mail security programs.”

See also  High Threats Recognized in X-Pressure Menace Intelligence Index 2023
- Advertisment -spot_img
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular