SERPENTINE#CLOUD is a financially motivated cybercrime intrusion set and phishing-led malware delivery operation active since at least November 2025. The actor conducts multi-wave campaigns centered on invoice-themed lures and primarily targets German-speaking businesses, with confirmed secondary targeting of organizations in the United Kingdom. Victimology includes small and medium-sized businesses, accounting-related organizations, and invoice-processing environments. The operation is characterized by abuse of Cloudflare Quick Tunnels and exposed WebDAV staging servers to deliver multi-stage malware chains. Initial access commonly relies on shortcut or script-based lure files that trigger staged downloaders and loaders, including WSF, BAT, and DLL-based execution paths. Observed tradecraft includes use of portable Python runtimes, shellcode loaders, process injection into explorer.exe, regsvr32-based execution, and evolving obfuscation across multiple loader generations. The actor has also used AutoIt-based persistence chains built around a renamed signed AutoIt interpreter and scheduled-task respawn mechanisms. SERPENTINE#CLOUD has delivered a broad malware arsenal including AsyncRAT, XWorm, Remcos, DcRat, VenomRAT, Violet v5, PureHVNC, PureCrypter, and a custom RAT referred to as PhilliVio. These payloads support remote access, credential theft, keylogging, screenshot capture, hidden VNC functionality, clipboard hijacking, DDoS capability, and durable backdoor access. Persistence mechanisms observed across waves include Startup-folder artifacts, Registry Run keys, scheduled tasks, hidden directories, and self-copying DLL behavior. A notable feature of the operation is parallel redundancy in post-compromise access. Distinct persistence chains identified as EcoOptimize, WealthWise, and UrbanEco were used to maintain access even after cleanup attempts. Two of these chains deployed Remcos configured for banking-fraud-oriented surveillance, including frequent targeted screenshots keyed to banking-related window titles, while another deployed PureHVNC through a multi-stage AutoIt-to-.NET crypter chain using process hollowing. Operational patterns indicate systematic campaign management, but repeated OPSEC failures have linked payload-building environments with command-and-control operations. The actor is best characterized as a financially motivated phishing and malware delivery cluster with strong emphasis on credential theft, surveillance of financial workflows, long-term persistence, and enabling downstream fraud.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
71 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated phishing and RAT delivery cluster abusing Cloudflare Quick Tunnels and WsgiDAV WebDAV servers to deliver multi-stage malware, often deploying multiple RAT families simultaneously against primarily German-speaking businesses and some UK targets.
A campaign/operator maintaining multi-chain Windows persistence via AutoIt BYOI (renamed AutoIt3.exe + obfuscated .a3x scripts) and scheduled tasks, delivering banking-fraud focused Remcos (targeted screenshots/keylogging) and PureHVNC for interactive access; shows single-operator control via highly similar Remcos configs and shared certificates/infra across deployments.
Phishing-driven intrusion activity leveraging Cloudflare Tunnels as infrastructure to deliver/deploy Python-based malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.