SERPENTINE#CLOUD is an ongoing malware delivery campaign documented by Securonix that abuses Cloudflare Tunnel subdomains under trycloudflare[.]com and WebDAV over HTTPS to stage payloads. The infection chain primarily uses phishing lures themed as invoices or payments to deliver malicious Windows shortcut (.lnk) files disguised as PDF documents. Observed .lnk execution chains use cmd.exe and robocopy to retrieve WSF/VBScript loaders, which then execute heavily obfuscated batch stages such as kiki.bat from remote WebDAV shares. The batch stage opens a decoy PDF, checks for antivirus processes including AvastUI.exe and avgui.exe, downloads bundled Python runtimes and malware into user-writable directories such as the user’s Contacts folder, establishes persistence via Startup-folder files including pws1.vbs, PWS.vbs, and startuppp.bat, and launches Python payloads.
The campaign’s Python stages include obfuscated loaders and shellcode runners. Securonix reported Python payloads such as Jun02_an.py, Jun02_as.py, Jun02_hv.py, Jun02_uk.py, and Jun02_xw3.py, with some samples obfuscated using the Kramer Python obfuscation tool. A decrypted stage, Jun02_an.py, was described as an in-memory shellcode loader using ctypes and embedded RC4-encrypted shellcode. The final loader invocation included python.exe run.py -i jun02_an.bin -k a.txt, and run.py implemented Early Bird APC injection by creating a suspended process such as notepad.exe, allocating memory, writing shellcode, queueing an APC, and resuming the thread. Securonix stated the shellcode resolved to a Windows PE payload with a strong signature match to Donut, indicating in-memory PE/.NET execution without writing the final payload to disk. The resulting access was assessed as RAT-like, with AsyncRAT or RevengeRAT cited as likely payload families.
Related reporting from Breakglass Intelligence described a structurally distinct but linked sample, final.bat, using the same TryCloudflare delivery mechanism and tradecraft consistent with SERPENTINE#CLOUD and VOID#GEIST. That sample downloaded Python 3.11.8 embedded distribution plus pip, psutil, cryptography, and pyaes, retrieved files.zip and add_to_startup.bat from TryCloudflare infrastructure, unpacked encrypted_loader.py with as_encrypted.bin and as_key.bin, installed under %APPDATA%\Microsoft\Windows\Crypto\RSA\Cache, and executed python encrypted_loader.py -f as_encrypted.bin explorer.exe to inject into explorer.exe. Breakglass also documented related BAT/VBScript/PowerShell delivery chains using voice-message lures in Israel, including voicemessage.bat variants that embedded an M4A decoy audio file and reconstructed hidden PowerShell download cradles from split environment variables to fetch second-stage payloads from TryCloudflare tunnels. Those samples displayed the message "Preparing to decode audiomessage" and used hidden PowerShell execution flags including -WindowStyle Hidden, -Nologo, and -ExecutionPolicy Bypass.
Observed infrastructure and indicators directly mentioned in reporting include trycloudflare subdomains such as flour-riding-merit-refers[.]trycloudflare[.]com, depot-arrange-zero-kai[.]trycloudflare[.]com, eastern-instructional-ant-jungle[.]trycloudflare[.]com, old-entire-sequences-reactions[.]trycloudflare[.]com, roger-conditioning-thriller-forms[.]trycloudflare[.]com, and requires-fortune-nutten-eligible[.]trycloudflare[.]com; Cloudflare anycast IPs 104.16.230[.]132 and 104.16.231[.]132; post-infection communications from notepad.exe to 192.169.69[.]26:7878 associated with djksncb.duckdns[.]org; and python.exe communications with domains resolving to 51.89.212[.]145, including nhvncpure[.]shop, nhvncpure[.]sbs, nhvncpure[.]click, and nhvncpure.duckdns[.]org. Attribution remains unknown or low-confidence in the cited reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Python-based encrypted shellcode loader delivered via TryCloudflare. It downloads Python 3.11.8 embedded distribution, installs dependencies, retrieves encrypted payload components, establishes persistence with add_to_startup.bat, and injects into explorer.exe.
Multi-stage infection chain delivered via phishing and malicious LNK/WSF/BAT stages that downloads Python components, establishes persistence via Startup folder scripts, and ultimately runs Python-based in-memory shellcode loaders (including Early Bird APC injection) to execute a Donut-packed payload and deploy a final RAT for full remote control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.