
Government-backed Hackers Use Cloudflare for Cyber Espionage in Malaysia
Government-backed hackers exploited Cloudflare’s storage services in a cyber espionage campaign targeting Malaysia, using hidden command-and-control (C2) systems to facilitate data exfiltration. The attack involved malicious infrastructure leveraging Cloudflare’s platform to obscure malicious activities, though no specific malware families or technical indicators were disclosed. The campaign was identified as part of a broader espionage effort, though no exact timeline or attribution to a specific nation-state actor was provided. No CVE IDs or numerical impact metrics, such as compromised systems or stolen data volumes, were mentioned. The primary focus of the operation appeared to be intelligence gathering, with phishing likely used as an initial access vector. The incident underscores the abuse of legitimate cloud services for covert cyber operations.