Cloudflared is Cloudflare’s tunnel client, a legitimate remote access utility that establishes outbound tunnels from a host to Cloudflare infrastructure. Although not malware in itself, it is frequently abused by threat actors as a stealthy persistence and remote access mechanism because it creates a durable command path without requiring inbound firewall exposure. In intrusion activity, operators have installed it as a persistent Windows service, used it to maintain secondary access after exploiting internet-facing management platforms, and leveraged it as a redundant backdoor alongside commercial remote management tools and other post-exploitation frameworks. Reported abuse includes deployment following compromise of remote monitoring and management systems and web-based administrative software, as well as use by ransomware affiliates during hands-on-keyboard operations. Its observed role is primarily post-compromise persistence, covert remote access, and defense evasion through blending with legitimate administrative tooling on Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attacks observed showed attackers registering outbound Cloudflare tunnels as persistent services on those endpoints... On endpoints managed through N-central, check ... for a Windows service registered as Cloudflared.
“...CVE-2025-26399 was just recently discussed by Microsoft and other vendors who have also observed active in-the-wild exploitation.”
"...followed immediately by the installation of Cloudflared from GitHub’s official release channel. This created a secondary tunnel-based access path..."
"...followed immediately by the installation of Cloudflared from GitHub’s official release channel. This created a secondary tunnel-based access path..."
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon launch, it connected to the C2 server, allowing the operator to execute commands on the compromised host... Cloudflared tunnels traffic through the Cloudflare network.
One shell then started cloudflared to publish a localhost service through a Cloudflare Quick Tunnel. Such a tunnel makes a laptop-hosted service reachable through an outbound connection, without a traditional inbound firewall rule.
One shell then started cloudflared to publish a localhost service through a Cloudflare Quick Tunnel. Such a tunnel makes a laptop-hosted service reachable through an outbound connection, without a traditional inbound firewall rule.
Three separate network-tunneling utilities were deployed to the host in the first 10 minutes of activity.
The compressed file containing XMRig was downloaded through the following command: > Bitsadmin /transfer
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attackers used Cloudflared/Cloudflare Tunnel as a persistence and remote access mechanism by registering it as a Windows service, allowing outbound connectivity that survives reboots and avoids inbound firewall exposure.
Cloudflared was used to establish a reverse tunnel/persistent access channel during an Akira intrusion, providing command-and-control style connectivity.
Cloudflare Tunnel client used legitimately for secure tunneling, but frequently abused to establish persistent remote access tunnels.
Legitimate Cloudflare tunneling client abused to establish a redundant remote access tunnel for persistence/backup C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.