216.73.216.6

Russian-Speaking Threat Actor Abuses Cloudflare & Telegram in Phishing Campaign

· Published 04/04/2025 11:47 · Modified 04/04/2025 17:32

Export JSON

Essential information

Published
04/04/2025 11:47
Modified
04/04/2025 17:32
Tags
2025-04-04 cloudflare dmca lnk ms-search open directory phishing powershell pyramid pyramid c2 python telegram
Related entities
1 intrusion sets (apt), 11 techniques (mitre), 1 malware

Description

A Russian-speaking threat actor has launched a new campaign using -branded pages themed around takedown notices. The attack abuses the protocol to deliver malicious files disguised as PDFs. Once executed, the malware communicates with a bot to report the victim's IP address before connecting to servers. The campaign leverages Pages and Workers services to host pages, and uses an to store malicious files. The infection chain includes and scripts, with incremental changes in tactics to evade detection. The actors' infrastructure spans multiple domains and IP addresses, primarily using 's network.

External references