SERPENTINE#CLOUD Returns with ClickFix and Brute Ratel
Score: 9/10

SERPENTINE#CLOUD Returns with ClickFix and Brute Ratel

SERPENTINE#CLOUD has updated its delivery chain using ClickFix lures and Cloudflare tunnels to deploy a multi-RAT suite including Brute Ratel C4 and PureHVNC.

Executive Summary

The threat actor known as SERPENTINE#CLOUD has resurfaced five weeks after a major remediation effort, targeting the same organization with an evolved delivery infrastructure. The campaign utilizes 'ClickFix' social engineering lures that leverage ephemeral Cloudflare tunnels to deliver a sophisticated multi-stage infection chain. This activity highlights the actor's persistence and ability to quickly rotate infrastructure after defensive interventions.

Technically, the actor has integrated Brute Ratel C4 as an evasion and injection layer, which utilizes Early Bird APC queue injection and PPID spoofing to deliver PureHVNC. The payload suite remains consistent with previous activity, featuring VenomRAT, AsyncRAT, and XWorm, all obfuscated via the Kramer Python bytecode obfuscator. The actor has also consolidated their Command and Control (C2) infrastructure to a specific AT&T residential subnet in Chicago, shifting away from previously sinkholed European hosting.

This campaign represents a high-urgency threat due to the actor's demonstrated ability to bypass standard EDR hooks using direct syscalls and process mitigation policies. Organizations should prioritize monitoring for anomalous WebDAV activity from rundll32 and suspicious parent-child process relationships involving notepad.exe and explorer.exe.

Key Details

Threat Name

SERPENTINE#CLOUD

Affects

—

Adversary

SERPENTINE#CLOUD

Malware/Tools

VenomRAT, AsyncRAT, XWorm, PureHVNC, Brute Ratel C4, Kramer, Donut, PureLogs

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure10
Technical Depth10

Sources