Vendor
Cloudflare
- First Reported
- Sep 8, 2026
- Latest Reported
- Sep 28, 2026
Reported Context (4)
- malware host, specifically associated with a SocGholish-style fake browser update lure hosted on free Cloudflare pages.eastus2[.]wac-azure[.]comIt was designated suspicious since it could be mimicking the Microsoft Jewelbug Campaigns Target Middle East and Asia With Espionage and Crypto Fraud
- Cloudflare fixes Containers cross-tenant flaw exposing customer data Cloudflare fixes Containers flaw that could expose other customers’ residual data
- Hijacked Adobe Document Cloud tenants, Cloudflare Workers, public code hosting, and legitimate management tools help the operation blend malicious activity with normal business infrastructure. CSuite Campaign Uses Phishing, M365 Session Theft and Remote-Access Tools Against US and EU Organizations
- second loader named "pf.ch" and allowed us to reconstruct its earlier delivery stages. The chain uses a Cloudflare Worker to inject JavaScript code stored on BNB Smart Chain and a ClickFix prompt impersonating Google ClearFake WebDAV Chains Deliver Amatera, ZigCryptoStealer and Unauthorized NetSupport
Malware (4)
Threat Actors (2)
MITRE ATT&CK (38)
Vendors (10)
Products (17)
Tools (15)
Industries (6)
Countries (12)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.