Introducing the 2026 Cloudflare Threat Report
2026-03-03 • Cloudflare •
Attachments
Cloudflare's 2026 threat report describes a shift toward high-trust exploitation, where adversaries favor stolen tokens, legitimate cloud services, SaaS integrations, and automation over bespoke exploits. The DPRK-relevant sections highlight North Korea's remote IT worker scheme, using deepfakes and fraudulent identities to place operatives on Western payrolls for espionage and illicit revenue. Cloudforce One also lists PatheticSlug as a North Korea-based actor abusing reputable cloud ecosystems, including Google Drive and Dropbox to host XenoRAT payloads and GitHub for covert C2. These examples matter because they show DPRK-linked operations blending into normal enterprise cloud traffic and identity workflows, reducing the value of defenses that focus only on obviously malicious infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | azurewebsites.net | 2024-01-17 | 2026-03-03 |