RAT
CloudFlare Tunnel
Cloudflare Tunnel (cloudflared) creates outbound-only tunnels from a host to Cloudflare, exposing internal services (RDP, SSH, SMB, HTTP) without inbound firewall rules. In the Swisscom intrusion described by The DFIR Report in June 2026, threat actors installed it as a Windows service on a domain controller for persistence and proxied RDP through it.
Tool overview
- Category
- RAT
- Research authors
- Not recorded
- Created
- 2024-08-02
- Last modified
- 2026-10-05
- Privileges
- User for standalone tunnels; Administrator to install the Windows service (runs as SYSTEM)
- Free / availability
- Yes
- Verification required
- No account required for Quick Tunnels; named tunnels require a Cloudflare account for creation and a tunnel token or credentials to run
- Supported platforms
Linux
Windows
macOS
Capabilities
Executables & installation paths
- Filename
- cloudflared.exe
- OriginalFileName
- Not recorded
- Description
- Not recorded
Installation paths
cloudflared.exe
C:\Program Files (x86)\cloudflared\cloudflared.exe
C:\Program Files\cloudflared\cloudflared.exe
FORENSIC EVIDENCE
Disk artifacts
- File
- C:\ProgramData\cloudflared\*
- Description
- Token file written by 'cloudflared service install <TOKEN>' on recent versions (service then runs with --token-file)
- OS
- Windows
- File
- C:\Windows\System32\config\systemprofile\.cloudflared\*
- Description
- Service-context config.yml, cert.pem and <tunnel-id>.json credentials for locally managed tunnels
- OS
- Windows
- File
- C:\Users\*\.cloudflared\*
- Description
- Per-user config.yml, cert.pem and tunnel credentials
- OS
- Windows
FORENSIC EVIDENCE
Event log artifacts
- EventID
- 7045
- ProviderName
- Service Control Manager
- LogFile
- System.evtx
- ServiceName
- Cloudflared
- Description
- Service installation (display name "Cloudflared agent", auto start). ImagePath contains 'tunnel run --token <TOKEN>' on older versions or '--token-file' on newer versions.
- EventID
- 1
- ProviderName
- Cloudflared
- LogFile
- Application.evtx
- Description
- cloudflared registers an event source named Cloudflared and logs "Cloudflared service starting" / "service arguments"
FORENSIC EVIDENCE
Registry artifacts
- Path
- HKLM\SYSTEM\CurrentControlSet\Services\Cloudflared
- Description
- Service key; ImagePath may contain the tunnel token
- Path
- HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Cloudflared
- Description
- Event log source registered during service install
FORENSIC EVIDENCE
Network artifacts
- Description
- Tunnel edge destinations and SNI hostnames (TCP 7844 for HTTP/2; UDP 7844 for QUIC)
- Domains
- region1.v2.argotunnel.com
- region2.v2.argotunnel.com
- us-region1.v2.argotunnel.com
- us-region2.v2.argotunnel.com
- _v2-origintunneld._tcp.argotunnel.com
- cftunnel.com
- h2.cftunnel.com
- quic.cftunnel.com
- Ports
- 7844
- Description
- Public DNS routing targets for named tunnels (CNAME targets, not tunnel edge connections)
- Domains
- *.cfargotunnel.com
- Ports
- Not recorded
- Description
- Temporary public HTTPS hostnames generated by Quick Tunnels
- Domains
- *.trycloudflare.com
- Ports
- 443
- Description
- Optional software update checks over HTTPS
- Domains
- update.argotunnel.com
- api.cloudflare.com
- Ports
- 443
FORENSIC EVIDENCE
Other artifacts
- Type
- WindowsServiceName
- Value
- Cloudflared
- Type
- CommandLine
- Value
- cloudflared.exe service install <TOKEN>
- Type
- CommandLine
- Value
- cloudflared.exe tunnel run --token <TOKEN>
- Type
- CommandLine
- Value
- cloudflared.exe tunnel --url http://localhost:8080
- Type
- RDPArtifact
- Value
- The Swisscom case reported RDP connections through Cloudflare Tunnel with a loopback source (::%16777216) in Windows event logs; this is a tunneling indicator, not unique to cloudflared
Detections
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/cloudflare_tunnel_processes_sigma.yml
- Description
- Detects potential processes activity of CloudFlare Tunnel RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/cloudflare_tunnel_network_sigma.yml
- Description
- Detects potential network activity of CloudFlare Tunnel RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/cloudflare_tunnel_files_sigma.yml
- Description
- Detects potential files activity of CloudFlare Tunnel RMM tool
- Sigma
- https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/cloudflare_tunnel_registry_sigma.yml
- Description
- Detects potential registry activity of CloudFlare Tunnel RMM tool
References
- https://cloudflare.com/products/tunnel/
- https://developers.cloudflare.com/tunnel/get-started/quick-tunnels/
- https://developers.cloudflare.com/tunnel/features/locally-managed-tunnels/create-local-tunnel/
- https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/configure-tunnels/tunnel-with-firewall/
- https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/do-more-with-tunnels/local-management/as-a-service/windows/
- https://github.com/cloudflare/cloudflared/blob/master/cmd/cloudflared/windows_service.go
- https://thedfirreport.com/2026/06/29/from-bing-search-to-ransomware-bumblebee-and-adaptixc2-deliver-akira-3/
Acknowledgements
- Person
- The DFIR Report
- Handle
- @TheDFIRReport
- Person
- Swisscom B2B CSIRT
- Handle
- Not recorded