RATs on the Loose Through Abused Cloudflare Tunnels

Amber | Attack Report

Threat actors are increasingly exploiting the Cloudflare Tunnel service to disseminate a diverse array of remote access trojans (RATs), such as AsyncRAT, GuLoader, VenomRAT, Remcos RAT, and Xworm. Initially identified in February 2024, this malicious activity has escalated significantly from May through July.

Reduce real exposure. Not just vulnerability volume.