BOFScale Turns Tailscale Into a Stealthy Memory-Only Tunnel — While a New Ransomware Claim Puts Target in the Spotlight + Video

Listen to this Post

Featured Image

A New Cybersecurity Warning Emerges

The cybersecurity landscape rarely gives defenders the luxury of dealing with one threat at a time. While ransomware operators continue looking for ways into large organizations, researchers are also uncovering increasingly sophisticated techniques designed to make malicious network activity blend into legitimate infrastructure.

Two developments highlighted in recent cybersecurity reporting illustrate that changing reality. The first involves BOFScale, a technique that reportedly turns a modified Tailscale daemon and client into an in-memory networking tool capable of tunneling traffic through WebSockets and CDN infrastructure. The second is an unverified ransomware claim involving Target, with the threat actor xpl0itrs allegedly claiming unauthorized access that disrupted parts of the retailer’s U.S. operations.

These stories are technically different, but they point toward the same larger problem: attackers are increasingly interested in living inside trusted infrastructure rather than announcing themselves through obviously malicious tools.

The BOFScale Technique

According to the material shared by Cybersecurity News Everyday on August 19, BOFScale operates by running a modified Tailscale daemon and client entirely in memory. The reported design uses Tailscale’s networking capabilities while attempting to avoid the conventional footprint associated with installing a normal networking application.

The technique reportedly tunnels TS2021 and DERP traffic over WebSockets, with CDN fronting used to make the traffic appear less suspicious. It also incorporates Headscale, SOCKS5 forwarding, and userspace networking.

That combination is important because modern defenders increasingly rely on network visibility and endpoint telemetry to distinguish legitimate remote-access traffic from malicious communications. A technique that can borrow familiar protocols, trusted services, and normal-looking web traffic can make that distinction significantly harder.

Why Running in Memory Matters

Memory-only execution is not automatically malicious, but it is attractive to attackers because it can reduce the number of artifacts written to disk.

Traditional security monitoring often looks for executable files, persistence mechanisms, suspicious installers, or newly created services. An operation that loads components directly into memory can potentially reduce some of those traditional indicators.

That does not make an attack invisible. Memory forensics, behavioral detection, process telemetry, network monitoring, and endpoint security products can still identify suspicious activity. The significance is that defenders may need to look beyond simple file-based indicators.

Tailscale Becomes Part of the Story

Tailscale itself is a legitimate networking technology. That distinction matters.

The cybersecurity concern surrounding BOFScale is not that Tailscale is inherently dangerous. Instead, the technique demonstrates how legitimate networking concepts can potentially be adapted for offensive purposes.

This is part of a broader security trend sometimes described as living-off-trusted-services behavior. Attackers increasingly attempt to abuse software, cloud platforms, identity systems, collaboration tools, remote-access technologies, and other services that organizations already consider legitimate.

The more familiar the infrastructure looks, the more difficult it can become for defenders to rely on reputation alone.

CDN Fronting Raises the Detection Challenge

The reported use of CDN fronting is particularly interesting from a defensive perspective.

CDNs are designed to distribute web traffic across infrastructure and improve availability, performance, and resilience. WebSockets are also widely used by legitimate applications that require persistent or near-real-time communication.

When malicious traffic is placed inside technologies that organizations already expect to see, network defenders may face a more complicated detection problem.

The objective is not necessarily to hide every packet. Instead, the attacker can attempt to make the communication look sufficiently ordinary that it does not immediately trigger an alert.

Headscale Adds Another Layer

The reported use of Headscale makes the BOFScale concept even more interesting from an architectural perspective.

Headscale is an open-source implementation of the control server concept associated with Tailscale’s networking model. In a legitimate environment, infrastructure like this can provide organizations with greater control over their private networking.

In an offensive context, however, the same architectural concepts can potentially be repurposed to create controlled private communication between compromised systems.

This is why defenders increasingly need to understand how a technology is being used, rather than simply asking whether the technology itself is legitimate.

SOCKS5 Forwarding Changes the Possibilities

SOCKS5 forwarding can provide another important capability by allowing traffic to pass through an intermediary.

For defenders, that creates a potentially dangerous scenario: a compromised machine does not necessarily need to communicate directly with every destination involved in an attack.

Instead, traffic can be routed through an intermediary layer, complicating attribution and network analysis.

The important security lesson is not that SOCKS5 is inherently malicious. It is that unexpected proxy behavior from systems that normally have no reason to act as network intermediaries should receive careful scrutiny.

Userspace Networking Can Reduce Traditional Visibility

The reported use of userspace networking is another element worth watching.

Traditional network infrastructure often depends on kernel-level networking components and predictable interfaces. Userspace networking can change how applications interact with network traffic and may create a different telemetry profile.

For defenders, this means unusual networking behavior should not automatically be dismissed simply because conventional network controls do not show an obvious malicious driver or service.

Behavior matters more than the presence or absence of a familiar artifact.

The Bigger Lesson From BOFScale

BOFScale is significant because it represents a broader evolution rather than simply another offensive tool.

Attackers have spent years moving away from obvious malware toward techniques that combine legitimate software, stolen credentials, cloud services, remote administration platforms, and native operating-system capabilities.

The logical next step is to combine those ideas with memory execution, encrypted communications, proxying, and trusted infrastructure.

That creates a security environment where defenders must understand entire chains of behavior rather than hunting for one recognizable malicious file.

The Target Ransomware Claim

An Alleged Attack on a Major Retailer

The second story circulating in the supplied report involves Target and the ransomware group xpl0itrs.

The post claims that Target experienced a ransomware incident allegedly linked to xpl0itrs, with unauthorized access reportedly disrupting U.S. retail operations.

This claim should be treated carefully.

At the time of writing, I could not independently verify the specific Target ransomware allegation through a reliable official Target disclosure or a high-confidence independent incident report. Therefore, it should be described as an allegation rather than an established breach.

Why the Word Allegedly Matters

Cybercrime groups frequently publish claims before victims confirm an incident.

Some claims eventually prove accurate. Others are exaggerated, misleading, recycled, or impossible to independently substantiate.

Dataminr has previously documented xpl0itrs making breach claims involving major organizations and specifically noted that some named victims had not officially confirmed the allegations.

That history makes independent verification especially important when reporting a new xpl0itrs claim.

xpl0itrs Is Not an Unknown Name

The group itself deserves attention even when an individual victim claim remains unverified.

Dataminr describes xpl0itrs as a financially motivated threat actor associated with supply-chain compromise, credential theft, and initial-access activity. The group has also been connected with activity involving developer environments and stolen credentials.

Cyble’s 2026 threat research also identified xpl0itrs among actors advertising compromised organizational access during the first quarter of the year.

That background means a new claim should not simply be ignored. It should instead be investigated without prematurely treating the allegation as confirmed fact.

Why Retailers Remain Attractive Targets

Retail organizations represent an unusually valuable combination of data, infrastructure, customers, suppliers, payment systems, and operational dependencies.

A major retailer may operate thousands of endpoints, stores, warehouses, online services, mobile applications, employee systems, third-party integrations, and logistics platforms.

Every additional connection creates another potential path for attackers.

Recent security research continues to highlight the pressure facing the retail sector. Black Kite reported extensive credential exposure and critical vulnerability findings across major retail and wholesale organizations and their supply chains.

Operational Disruption Can Be More Valuable Than Data

Modern ransomware is not solely about stealing databases.

Attackers can potentially generate enormous pressure by interfering with business operations, including inventory systems, logistics, internal applications, employee services, customer-facing systems, and payment-related infrastructure.

That is particularly important for retailers because disruption can quickly become visible to customers.

A security incident that prevents employees from accessing critical systems can become a business crisis long before investigators determine exactly what data was accessed.

Ransomware Has Become a Business-Level Attack

The modern ransomware model increasingly targets business authority rather than simply technical infrastructure.

Zscaler ThreatLabz recently found evidence that ransomware campaigns were increasingly compromising managers and business leaders whose positions could provide valuable access or influence.

That finding changes the way organizations should think about ransomware defense.

The most dangerous employee account may not belong to the person who manages the servers. It may belong to someone who controls approvals, financial processes, sensitive documents, or access to business-critical systems.

The Connection Between the Two Stories

Trusted Infrastructure Is the Common Theme

At first glance, BOFScale and the alleged Target incident have little in common.

One concerns a networking technique. The other concerns an alleged ransomware intrusion.

But there is a deeper connection: modern attackers increasingly exploit trust.

BOFScale reportedly attempts to use legitimate networking technologies and web infrastructure as part of a covert communication architecture.

Ransomware groups frequently abuse legitimate credentials, remote-access tools, cloud platforms, identity systems, and business applications.

In both cases, the attacker benefits when defenders assume that familiar infrastructure is automatically safe.

The Security Perimeter Is Disappearing

The traditional cybersecurity model imagined a relatively simple boundary: protect the corporate network, block malicious traffic, and keep attackers outside.

That model is becoming less realistic.

Employees work remotely. Applications communicate with cloud services. Vendors receive privileged access. Developers connect to external repositories. Companies deploy SaaS platforms. Network infrastructure crosses multiple providers.

The result is an environment where the “inside” and “outside” of an organization are increasingly difficult to define.

Identity Is Becoming the New Perimeter

Credentials have consequently become extraordinarily valuable.

If an attacker acquires a legitimate identity, they may not need to deploy traditional malware immediately.

They can potentially authenticate, move through applications, access cloud resources, impersonate employees, and search for additional privileges.

That is one reason security programs increasingly emphasize phishing-resistant authentication, least privilege, session monitoring, privileged access management, and continuous identity verification.

Detection Must Become Behavioral

A file hash can identify a known malicious executable.

But what happens when there is no suspicious executable?

What happens when the attacker uses a legitimate networking component, a stolen account, a normal cloud provider, an encrypted WebSocket connection, or an administrative utility?

The answer is behavioral detection.

Security teams need to understand what systems normally do and identify meaningful deviations from that baseline.

Network Monitoring Still Matters

Memory-based execution does not eliminate network evidence.

A malicious process still needs to communicate.

That makes outbound traffic patterns, unusual proxy activity, unexpected WebSocket connections, abnormal DNS behavior, unfamiliar endpoints, and anomalous authentication events important sources of evidence.

The strongest defenses combine endpoint, identity, network, cloud, and application telemetry instead of depending on a single detection layer.

Deep Analysis: Commands for Defenders

Command 1 — Hunt for Unexpected Tunneling

Security teams should identify endpoints generating unusual persistent WebSocket connections, particularly where the application normally has no business reason to maintain them.

The goal is not to block WebSockets universally. Blocking legitimate application traffic would create unnecessary operational problems.

Instead, defenders should identify unusual combinations of process identity, destination, duration, frequency, and user context.

Command 2 — Audit Tailscale Deployments

Organizations using Tailscale or comparable networking platforms should maintain an authoritative inventory of approved installations, nodes, administrators, authentication methods, and expected network relationships.

Any unmanaged instance deserves investigation.

The key question is simple: Who installed it, why was it installed, and what systems can it reach?

Command 3 — Monitor Headscale Infrastructure

Where Headscale exists legitimately, administrators should carefully monitor changes to nodes, authentication keys, configuration, and administrative access.

An unexpected new node or authentication event should not be treated as routine configuration noise.

Command 4 — Investigate Proxy Behavior

SOCKS5 activity can be legitimate, but unexpected proxying from endpoints that normally have no proxy function should be investigated.

Defenders should correlate proxy behavior with process execution, account activity, network destinations, and recent administrative changes.

Command 5 — Look Beyond Disk Artifacts

Endpoint investigations should include memory and process telemetry when compromise is suspected.

File-based scanning alone can miss attacks that deliberately minimize disk artifacts.

Memory analysis, command-line telemetry, process ancestry, module loading, and unusual network behavior can provide additional evidence.

Command 6 — Protect Privileged Identities

Organizations should prioritize phishing-resistant MFA and strong identity controls for administrators, executives, finance personnel, developers, and other high-value accounts.

Ransomware operators increasingly understand organizational structures.

Security teams should therefore protect people according to the access and authority they possess, not simply their job titles.

Command 7 — Reduce Lateral Movement

Network segmentation can limit the damage caused by a compromised account or endpoint.

A workstation should not automatically be able to reach every server, management interface, database, or administrative system.

The fewer unnecessary pathways an attacker has, the harder it becomes to transform one compromised endpoint into an enterprise-wide incident.

Command 8 — Monitor Remote Access

Remote-access infrastructure remains one of the most attractive attack surfaces.

Security teams should continuously review VPN accounts, remote-management tools, network overlays, privileged sessions, and unusual geographic or behavioral authentication patterns.

Command 9 — Validate Ransomware Claims Carefully

When a threat actor claims an organization has been compromised, security teams should avoid both extremes.

Do not automatically assume the claim is true.

Do not automatically dismiss it either.

Instead, trigger an internal validation process that examines authentication logs, endpoint alerts, network traffic, cloud activity, data-access records, and backup integrity.

Command 10 — Treat Supply Chains as Part of the Attack Surface

A retailer cannot protect itself completely by securing only its own infrastructure.

Third-party software, contractors, logistics providers, SaaS platforms, development tools, and cloud services can create indirect paths into sensitive environments.

The attack surface now extends beyond corporate ownership.

Command 11 — Build Detection Around Normal Behavior

Security teams should establish behavioral baselines for critical servers, employee endpoints, networking tools, and administrative accounts.

A legitimate application performing an unusual action can be more suspicious than an obviously malicious application doing something expected.

Context is increasingly the difference between noise and detection.

Command 12 — Prepare for Memory-Only Incidents

Incident response plans should include procedures for preserving volatile evidence.

If investigators immediately shut down a potentially compromised machine, valuable evidence existing only in memory may disappear.

Organizations should therefore ensure their incident response teams understand how to preserve volatile data safely and appropriately.

Command 13 — Monitor Authentication Tokens

Because modern threat actors increasingly target credentials and tokens, organizations should monitor unusual token creation, privilege escalation, OAuth activity, session reuse, and authentication from unexpected environments.

Token theft can allow an attacker to bypass some of the protections that would otherwise stop a conventional password-based intrusion.

Command 14 — Harden Developer Environments

xpl0itrs’ broader activity has been associated with developer environments and supply-chain compromise, making developer credentials and CI/CD infrastructure particularly important security assets.

Build systems should receive security controls comparable to production infrastructure.

A compromised developer environment can become a bridge into repositories, cloud accounts, secrets, packages, and downstream customers.

Command 15 — Make Backups Operationally Useful

Backups are not enough if they can be encrypted or deleted by attackers.

Organizations should maintain isolated, access-controlled recovery copies and regularly test restoration.

The real ransomware defense is not simply having backups.

It is knowing that the organization can actually recover.

What Undercode Say:

The Real Threat Is Trust Abuse

The most important lesson from these reports is not one particular tool or ransomware group.

It is the weaponization of trust.

Attackers increasingly want their traffic to look legitimate, their accounts to look authentic, and their infrastructure to look familiar.

Memory-Only Techniques Raise the Bar

Techniques such as the reported BOFScale architecture demonstrate why endpoint security cannot rely exclusively on detecting files written to disk.

Security teams need visibility into process behavior, memory, authentication, and communications.

Legitimate Software Can Become an Offensive Weapon

Tailscale, WebSockets, CDNs, SOCKS5, cloud platforms, and administrative tools all have legitimate uses.

The challenge is determining when legitimate technology is being used outside its expected context.

Detection Needs Context

A WebSocket connection is not automatically malicious.

A Tailscale installation is not automatically malicious.

A proxy is not automatically malicious.

But an unexplained combination of all three on an endpoint that should not use them can become a very different story.

Retail Has a Structural Problem

Retailers remain attractive because they combine enormous operational footprints with valuable customer information.

They also depend heavily on third-party services and distributed infrastructure.

That makes retail cybersecurity an ecosystem problem rather than merely an endpoint problem.

Ransomware Is Becoming More Human

The increasing targeting of managers demonstrates that attackers are studying organizational structures.

They are not simply looking for computers.

They are looking for people who can unlock systems, approve payments, access sensitive information, or influence decisions.

xpl0itrs Deserves Monitoring

Even though the specific Target claim remains unverified, xpl0itrs has an established record of high-profile breach claims and activity associated with credential theft and supply-chain compromise.

That makes the actor worth tracking without turning every allegation into a confirmed incident.

Claims Are Not Evidence

Cybersecurity journalism has a responsibility to separate threat-actor claims from independently verified incidents.

A leak-site listing, social-media post, or ransomware announcement is evidence that a claim was made.

It is not automatically proof that the claimed compromise happened exactly as described.

The Target Story Needs Confirmation

At present, the reported Target incident should therefore be described as an allegation.

If Target confirms unauthorized access or operational disruption, the severity and scope can then be evaluated using primary evidence.

Until then, the responsible position is to monitor rather than declare the breach confirmed.

Defenders Should Assume Less

Security architecture should not assume that familiar software is safe simply because it is widely used.

It should ask whether the software is being used in a way that matches the organization’s intended architecture.

Zero Trust Becomes More Practical

These developments reinforce the value of zero-trust principles.

Every connection should have a reason.

Every privileged action should have context.

Every identity should have an appropriate level of access.

Visibility Is the New Advantage

Attackers benefit when defenders cannot see what is happening.

Organizations that combine endpoint, identity, network, cloud, and application telemetry can make stealth considerably harder.

Speed Matters

Ransomware becomes significantly more damaging when attackers have time to explore an environment.

Early detection can prevent attackers from reaching backup systems, privileged accounts, sensitive databases, and critical operational infrastructure.

Memory Analysis Should Not Be Optional

For high-value systems, volatile evidence can be critical.

Organizations should ensure their response teams can investigate suspicious processes and memory-resident activity instead of depending exclusively on filesystem artifacts.

Network Architecture Matters

Segmentation can prevent a compromised endpoint from becoming an enterprise-wide disaster.

The objective is not perfect prevention.

The objective is limiting the

Authentication Is Critical Infrastructure

Credentials should be treated as security-sensitive assets.

A stolen account can provide attackers with an apparently legitimate doorway into an organization.

Developers Need Stronger Protection

Modern supply-chain attacks demonstrate that development environments can become high-value targets.

Source repositories, CI/CD pipelines, package registries, cloud credentials, and signing keys all deserve serious protection.

Retailers Need Ecosystem Security

A retailer’s security is partly determined by the security of its suppliers and technology partners.

Vendor risk management should therefore move beyond annual questionnaires toward continuous assessment.

The Attack Surface Keeps Growing

Every new SaaS application, remote-access platform, API, integration, and cloud service expands the number of relationships defenders must understand.

Security teams cannot protect what they do not know exists.

BOFScale Is a Warning Sign

The reported architecture is a reminder that offensive security techniques are becoming increasingly creative in their use of legitimate networking technologies.

Defenders should expect more experimentation in this direction.

CDN Abuse Will Remain Attractive

Infrastructure that naturally handles massive volumes of legitimate web traffic provides attackers with an attractive environment for blending communications.

Detection therefore needs to focus on behavioral anomalies rather than simple reputation-based blocking.

Ransomware Will Continue Evolving

Ransomware groups are unlikely to abandon extortion.

Instead, they are likely to continue experimenting with credential theft, social engineering, data theft, cloud compromise, supply-chain attacks, and operational disruption.

The Human Layer Cannot Be Ignored

Technology can stop many attacks.

But attackers continue to target humans because humans control identities, approvals, relationships, and access.

Security awareness and strong authentication therefore remain essential.

Recovery Is a Security Capability

Organizations should measure cybersecurity not only by how many attacks they block but also by how quickly they can recover when something gets through.

Resilience is becoming as important as prevention.

The Biggest Mistake Is Complacency

An organization can have modern endpoint protection and still be vulnerable to stolen credentials, trusted tools, compromised suppliers, or malicious insiders.

Security is a system, not a single product.

Trust Must Be Earned Continuously

The future of cybersecurity will increasingly revolve around continuous verification.

A trusted application should remain trusted because its behavior is consistent and authorized, not merely because its name appears on an allowlist.

Attackers Are Playing the Long Game

Sophisticated campaigns can involve reconnaissance, credential theft, persistence, lateral movement, data discovery, and delayed extortion.

The earlier defenders detect unusual behavior, the more opportunities they have to interrupt that chain.

The Two Reports Point in the Same Direction

BOFScale illustrates stealth through networking and trusted technology.

The Target allegation illustrates the continuing threat of ransomware and extortion against large organizations.

Together, they demonstrate how modern cyberattacks increasingly rely on blending in rather than breaking in loudly.

The Defensive Priority Is Clear

Organizations should invest in identity security, behavioral detection, network visibility, segmentation, memory-aware incident response, supply-chain security, and tested recovery procedures.

Those controls address the underlying techniques rather than chasing one threat name at a time.

Cybersecurity Is Moving Beyond Malware

The era when security teams could focus primarily on malicious executables is disappearing.

The next generation of attacks will increasingly involve identities, infrastructure, legitimate applications, cloud services, and trusted communication channels.

The Bottom Line

The reported BOFScale technique and the unverified Target ransomware claim should not be viewed as isolated cybersecurity headlines.

They are symptoms of a larger transition.

Attackers are becoming better at hiding inside normal business activity, while defenders must become better at recognizing abnormal behavior within that normal activity.

Verification Status

❌ The specific claim that Target suffered a ransomware incident linked to xpl0itrs and that the incident disrupted U.S. retail operations could not be independently confirmed through a reliable primary source during this review, so it should remain classified as an allegation.

✅ xpl0itrs is a documented threat actor associated with credential theft, supply-chain compromise, initial-access activity, and multiple high-profile breach claims. Dataminr has specifically documented the group’s activities and warned that some of its public victim claims remained unverified.

✅ The BOFScale description in the supplied post is technically plausible as a description of an offensive networking concept involving modified Tailscale components, WebSockets, CDN fronting, Headscale, SOCKS5 forwarding, and userspace networking, but I could not independently locate the referenced BOFScale research page in searchable sources, so the detailed implementation should be treated as reported rather than independently verified.

Prediction

(-1) Trusted Infrastructure Will Become an Increasingly Dangerous Blind Spot

As attackers continue abusing legitimate networking tools, cloud services, identity systems, and remote-access technologies, organizations that depend heavily on allowlists and reputation-based detection will face increasing difficulty distinguishing authorized activity from malicious behavior.

(+1) Behavioral Detection Will Become the Defensive Standard

Security platforms will increasingly correlate process activity, identity events, network connections, authentication behavior, and cloud activity instead of relying on individual indicators. This will make sophisticated living-off-the-land and memory-resident techniques harder to hide.

(-1) Retail Will Remain a High-Value Ransomware Target

Large retailers combine extensive infrastructure, valuable customer information, operational dependencies, and enormous pressure to maintain availability. Those characteristics make them attractive targets for extortion campaigns even when individual threat claims turn out to be exaggerated.

(+1) Identity Security Will Become More Important Than Ever

Organizations that deploy phishing-resistant authentication, tightly controlled privileges, strong session monitoring, and aggressive credential protection will be better positioned to prevent attackers from turning one stolen identity into an enterprise-wide compromise.

(+1) The Strongest Organizations Will Assume Compromise

The most resilient security programs will increasingly operate on the assumption that attackers may eventually bypass one defensive layer.

Their advantage will come from detecting unusual behavior quickly, limiting lateral movement, protecting critical identities, maintaining isolated backups, and recovering before an intrusion becomes a business catastrophe.

▶️ Related Video (70% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: x.com
Extra Source Hub (Possible Sources for article):
https://www.github.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube