Executive Summary
The threat actor known as SERPENTINE#CLOUD has resurfaced five weeks after a major remediation effort, targeting the same organization with an evolved delivery infrastructure. The campaign utilizes 'ClickFix' social engineering lures that leverage ephemeral Cloudflare tunnels to deliver a sophisticated multi-stage infection chain. This activity highlights the actor's persistence and ability to quickly rotate infrastructure after defensive interventions.
Technically, the actor has integrated Brute Ratel C4 as an evasion and injection layer, which utilizes Early Bird APC queue injection and PPID spoofing to deliver PureHVNC. The payload suite remains consistent with previous activity, featuring VenomRAT, AsyncRAT, and XWorm, all obfuscated via the Kramer Python bytecode obfuscator. The actor has also consolidated their Command and Control (C2) infrastructure to a specific AT&T residential subnet in Chicago, shifting away from previously sinkholed European hosting.
This campaign represents a high-urgency threat due to the actor's demonstrated ability to bypass standard EDR hooks using direct syscalls and process mitigation policies. Organizations should prioritize monitoring for anomalous WebDAV activity from rundll32 and suspicious parent-child process relationships involving notepad.exe and explorer.exe.
