Cyber Espionage Campaign Targets Malaysian Organizations via Cloudflare Storage
Article Content
- •Attackers exploited Cloudflare storage to exfiltrate data from Malaysian networks.
- •An Azure virtual machine was central to orchestrating the cyber espionage campaign.
- •The operation targeted multiple government-linked organizations, indicating a high level of planning.
A sophisticated cyber espionage campaign has been uncovered, targeting multiple Malaysian government organizations. Attackers exploited a Cloudflare-hosted storage endpoint to exfiltrate sensitive files from compromised networks. The operation utilized an Azure virtual machine (IP: 20.17.161.118) to orchestrate attacks, employing custom tools for stealthy data extraction. The campaign's structured attack chain indicates a high level of planning and execution. Security researchers have confirmed that the attackers were able to pull files without triggering alarms, raising concerns about the effectiveness of current security measures. The full scope of the data stolen is still being assessed, but the operation has significant implications for national security. Current status indicates ongoing investigations by cybersecurity teams to mitigate the threat.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…