TryCloudflare refers to a threat-actor tactic that abuses Cloudflare services to hide malicious activity, leveraging Cloudflare's edge network to obfuscate command-and-control or payload delivery.
TryCloudflare is a technology platform tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed January 15, 2026; most recent activity July 3, 2026.
TryCloudflare refers to a threat-actor tactic that abuses Cloudflare services to hide malicious activity, leveraging Cloudflare's edge network to obfuscate command-and-control or payload delivery. This approach makes detection and takedown harder because traffic can appear to originate from legitimate Cloudflare infrastructure. The technique gained prominence as the AsyncRAT campaign leveraged Cloudflare services to conceal its operations, highlighting how legitimate platforms can be repurposed for cyber threats.
A phishing campaign has been identified that utilizes a fake invoice PDF to deliver multiple remote access trojans (RATs), primarily AsyncRAT, along with VenomRAT and XWorm. The attack begins with a phishing email…
The AsyncRAT malware has resurfaced, utilizing TryCloudflare tunnels and Dropbox links for delivery, which allows it to bypass traditional security measures. This campaign targets various organizations, enabling…
Threat actors have leveraged phishing emails to initiate a multi-stage intrusion chain that deploys the AsyncRAT remote access trojan. This operation utilizes Cloudflare's free-tier infrastructure and legitimate Python…
TryCloudflare refers to a threat-actor tactic that abuses Cloudflare services to hide malicious activity, leveraging Cloudflare's edge network to obfuscate command-and-control or payload delivery.
The most recent intelligence report mentioning TryCloudflare on ThreatCluster is dated July 3, 2026. Activity was first observed January 15, 2026, giving a tracked span from then to July 3, 2026.
Across ThreatCluster reporting, TryCloudflare most frequently co-occurs with Malware, Phishing, Trojan, AsyncRAT Campaign, Cloudflare, among 12 tracked related entities.
The most significant recent cluster is “Phishing Campaign Distributes AsyncRAT, VenomRAT, and XWorm via Fake Invoice PDF” (2 articles · Updated July 2, 2026). TryCloudflare appears across 3 threat clusters in total, listed above with sources.
TryCloudflare appears in 4 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.