Target Industry
Indiscriminate, opportunistic targeting.
Overview
A new malware campaign called SERPENTINE#CLOUD has been discovered by Securonix. The campaign uses Cloudflare Tunnel subdomains to host and deliver malicious payloads via phishing emails.
Impact
The SERPENTINE#CLOUD malware campaign can have several significant impacts on organisations. The malware can steal sensitive data, including personal information, financial records, and intellectual property, leading to data breaches and potential regulatory fines. The infection process can disrupt normal business operations, causing downtime and affecting productivity. This can be particularly damaging for critical infrastructure and services. The malware utilises legitimate cloud services to evade detection and employs extensive code obfuscation.
Exploitation
The malware uses Cloudflare Tunnel subdomains to host and deliver malicious payloads via phishing emails. The infection chain starts with phishing emails containing Windows shortcut (LNK) files disguised as documents. Payload execution involves multiple stages, including Python-based shellcode loaders and Donut-packed payloads (an open-source tool designed to generate shellcode payloads that can be executed entirely in memory).
Indicators of Compromise
An extensive list of the indicators of compromise can be found in the analysis of the malware by Securonix.
Containment, Mitigations & Remediations
It is highly recommended to educate employees on phishing awareness, to avoid downloading files or attachments from unsolicited emails, especially ZIP, RAR, ISO, and PDF files. Enable file extension visibility in Windows to identify suspicious file types. Monitor common malware staging directories and script-related activity in writable directories, such as the user’s home directory.
Deploy robust endpoint logging capabilities, including Sysmon and PowerShell logging, to detect suspicious activities. Monitor traffic to Cloudflare Tunnel subdomains and other suspicious domains listed in the report. There are also threat hunting rules to aid detection on the Securonix webpage.
Threat Landscape
Cloudflare Tunnels are used globally by a broad range of organisations, from small businesses to large enterprises, to securely connect their infrastructure to the internet. The campaign has been noted to target the United States, United Kingdom, Germany, and other regions in Europe and Asia.
Threat Group
The identity of the threat actors is unknown, but they are noted for their English fluency. The campaign may be a continuation of previous attacks or involve different actors using similar tactics.
TTPs
| T1566.001: | Phishing: Spearphishing Attachment |
| T1071.001: | Application Layer Protocol: Web Protocols |
| T1132: | Data Encoding |
| T1572: | Protocol Tunneling |
| T1027: | Obfuscated Files or Information |
| T1027.010: | Command Obfuscation |
| T1027.012: | LNK Icon Smuggling |
| T1027.013: | Encrypted/Encoded File |
| T1036: | Masquerading |
| T1218: | System Binary Proxy Execution |
| T1564.006: | Hide Artifacts: Run Virtual Instance |
| T1021.007: | Remote Services: Cloud Services |
| T1055: | Process Injection |
| T1059.001: | Command and Scripting Interpreter: PowerShell |
| T1059.003: | Command and Scripting Interpreter: Windows Command Shell |
| T1059.005: | Command and Scripting Interpreter: Visual Basic |
| T1059.006: | Command and Scripting Interpreter: Python |
| T1204.001: | User Execution: Malicious Link |
| T1204.002: | User Execution: Malicious File |
| T1620: | Reflective Code Loading |
| T1072: | Software Deployment Tools |
| T1041: | Exfiltration Over C2 Channel |
Further Information













