Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
MalwareRansomwareExploits 3 CVEs

Cloudflared

Cloudflared is the Cloudflare Tunnel client repeatedly observed in intrusion activity as a tunneling and remote-access utility rather than bespoke malware. In the provided reporting, threat actors used cloudflared.exe to establish persistent tunnels back to attacker-controlled infrastructure and create secondary backdoor communications paths for redundant access. It was observed in Akira ransomware intrusions, including one intrusion where an affiliate installed Cloudflare Tunnel via MSI and ran cloudflared.exe tunnel run -- token ..., and in a broader SonicWall SSL VPN campaign where protocol tunneling via Cloudflare Tunnel was documented among Akira tradecraft. It was also deployed during exploitation of SolarWinds Web Help Desk, where the attacker installed Cloudflared from GitHub’s official release channel after gaining code execution and used it as a secondary tunnel-based access path alongside other remote tooling. High-confidence behaviors in the content include persistent tunnel establishment, backdoor communications, and support for hands-on-keyboard post-compromise operations. Associated activity in the same incidents included reconnaissance, credential theft, lateral movement, data staging/exfiltration, and ransomware deployment by Akira affiliates. The content specifically identifies the executable name cloudflared.exe and references command-line tunnel execution as notable indicators.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

3 CVES
CVE-2025-26399Unauthenticated AjaxProxy Deserialization RCE in SolarWinds Web Help DeskExploited in the wild

“...CVE-2025-26399 was just recently discussed by Microsoft and other vendors who have also observed active in-the-wild exploitation.”

via security affairssecurityaffairs.com
CVE-2025-40551Unauthenticated RCE in SolarWinds Web Help Desk Deserialization

"...followed immediately by the installation of Cloudflared from GitHub’s official release channel. This created a secondary tunnel-based access path..."

via cyber security newscybersecuritynews.com
CVE-2025-40536Security Control Bypass in SolarWinds Web Help Desk

"...followed immediately by the installation of Cloudflared from GitHub’s official release channel. This created a secondary tunnel-based access path..."

via cyber security newscybersecuritynews.com
MITRE ATT&CK

Techniques & procedures

18 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1588.002ToolEvidence2

The content repeatedly states that threat actors 'obtained,' 'acquired,' or 'used' publicly available, open-source, legitimate, or modified tools such as Mimikatz, Cobalt Strike, PsExec, Empire, Impacket, and many others.

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence1

"Huntress confirmed active SolarWinds Web Help Desk exploits... Attackers exploited unpatched versions to run code remotely"

Execution

1 technique
T1059.001PowerShellEvidence1

"executed a rapid sequence of base64-encoded PowerShell commands"

Persistence

1 technique
T1543.003Windows ServiceEvidence2

They made Localtonet persistent with the help of Non-Sucking Service Manager (NSSM)... If the -p flag is specified... a service for the Gost tool will be installed... If -t key is passed... it installs and configures cloudflared in the system.

Privilege Escalation

1 technique
T1543.003Windows ServiceEvidence2

They made Localtonet persistent with the help of Non-Sucking Service Manager (NSSM)... If the -p flag is specified... a service for the Gost tool will be installed... If -t key is passed... it installs and configures cloudflared in the system.

Discovery

2 techniques
T1016System Network Configuration DiscoveryEvidence1

As the attacker, I need to have some knowledge about the victim’s network environment to configure the tunnel to allow access to the Private Network. In this case, a simple ipconfig from the victim machine gets me some basic details demonstrating the IP address and subnet of the machine.

T1046Network Service DiscoveryEvidence1

Here we see the results of an nmap scan conducted from my attack machine, across the Cloudflare Tunnel, against Victim File Server.

Lateral Movement

4 techniques
T1021Remote ServicesEvidence1

... TightVNC ... PsExec ... OpenSSH ... PowerShell Remoting (PSRemoting) ... RDP Patcher ... VS Code Tunnel ... Cloudflared ...

T1021.001Remote Desktop ProtocolEvidence1

I can pre-configure a tunnel on the Cloudflare Dashboard with a Public Hostname for access.not-malicio.us hosting an RDP service at localhost:3389... Here we can see the successful connection established using Cloudflared’s access command, and the resulting RDP session pointing to localhost:3389.

T1021.002SMB/Windows Admin SharesEvidence1

For SMB, the same process can be used... Adding in the capability to exfiltrate data using nothing more than SMB enhances the threat Cloudflared poses in an obvious and serious way.

T1570Lateral Tool TransferEvidence1

Adding in the capability to exfiltrate data using nothing more than SMB enhances the threat Cloudflared poses in an obvious and serious way.

Command and Control

7 techniques
T1071Application Layer ProtocolEvidence2

Upon launch, it connected to the C2 server, allowing the operator to execute commands on the compromised host... Cloudflared tunnels traffic through the Cloudflare network.

T1090ProxyEvidence12

deploying Chisel reverse SOCKS tunnels

T1090.001Internal ProxyEvidence1

Private Networks allows an administrator to provide access to an entire CIDR range through the tunnel, allowing a client device, such as an attacker’s machine, network access as though they were physically collocated with the victim machine hosting the tunnel... From here, an attacker can interact with any device in the private network.

T1090.002External ProxyEvidence6

Five hours later, the attacker dropped EtherRAT and set up a Cloudflare tunnel using a renamed copy of cloudflared... A reverse shell on port 43301 and multiple Chisel SOCKS tunnels gave them layered persistence

T1105Ingress Tool TransferEvidence8

That script downloaded and installed an MSI package in the background with no visible indication to the user. Separately, the attacker deployed EtherRAT... Five hours later, the attacker dropped EtherRAT and set up a Cloudflare tunnel using a renamed copy of cloudflared.

T1219Remote Access ToolsEvidence3

along with a Cloudflare tunnel for persistent access

T1572Protocol TunnelingEvidence5

Incident #2 The threat actor almost immediately installed Cloudflare’s freely available tunnelling software here, C :\ProgramData\windows_update.exe , followed by the download and execution of another dual-use agent, Radmin [T1572 – Protocol Tunneling ] [T1219 – Remote Access Software]

Exfiltration

1 technique
T1048Exfiltration Over Alternative ProtocolEvidence1

Adding in the capability to exfiltrate data using nothing more than SMB enhances the threat Cloudflared poses in an obvious and serious way.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities3

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping18

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.