Cloudinary virus: why res.cloudinary.com shows up in malware alerts, and what to do if a loader fetched its pictures
Cloudinary is a legitimate image hosting service, not a virus, but criminals upload JPG pictures that hide malware and point loaders at them. In September 2026 URLhaus listed eleven such pictures on res.cloudinary.com, seven tagged RemcosRAT and one PureLogsStealer. If you only saw the address in a log, nothing is proven. If a program on your Windows PC fetched one, act now.
Facts checked October 8, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Programs like a script, loader or program that downloads JPG pictures from res.cloudinary.com usually arrive in groups; a free scan lists the companions that are easy to miss.
Do it yourself · free Remove Cloudinary virus (malware hidden in pictures on res.cloudinary.com) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Cloudinary virus (malware hidden in pictures on res.cloudinary.com): summary
| Type | A legitimate image service abused to host JPG pictures that hide Remcos and PureLogs malware |
|---|---|
| Risk | High if a loader on your PC fetched one of the pictures. None if you only saw res.cloudinary.com in a log or on a website |
| Symptoms | Often none. Unknown Run key entries, msbuild.exe or caspol.exe running with no reason, a Defender alert |
| How to get rid of it | Change passwords from another device, run Microsoft Defender Offline, remove startup entries, reset Windows if unsure |
| Our check (8 October 2026) | Plain request from our server: HTTP 404 from Cloudinary at the bare address. Reported pictures not requested |
| Platform | Windows. Nothing we read says Mac or phones are affected |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 8 more facts
| Detection names | Microsoft uses Backdoor:Win32/Remcos for Remcos. We found no published Microsoft name for these eleven exact files; we did not scan them |
|---|---|
| Name | Cloudinary virus |
| Domain registered | 24 May 2011 |
| Evidence | 11 write-ups by security sites; details still limited |
| First seen | 9 September 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 8 October 2026 |
Facts checked on 8 October 2026 against the URLhaus data for res.cloudinary.com in our job record, RDAP, one plain request from our server (no browser), Cloudinary's documentation and Acceptable Use Policy, and reports by Microsoft, MITRE ATT&CK, K7 Labs, Seqrite and ANY.RUN. We did not download the pictures and infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.
What Cloudinary is, and why its address shows up in malware reports
Cloudinary is not a virus. It is a legitimate image and video hosting service that many online shops, news sites and apps use to store and resize their pictures, and res.cloudinary.com is the address those pictures are served from. Anyone can open an account and upload files, and criminals sometimes do. They upload JPG pictures that hide malware code and then point a loader at the picture's address, because a download from a well known image service looks harmless.
In September 2026 the abuse.ch project URLhaus listed eleven such pictures on res.cloudinary.com, spread over six accounts. Seven were tagged RemcosRAT, a remote access trojan for Windows, one was tagged PureLogsStealer, and nine carried the tag stego, which means data hidden inside the picture. All eleven were offline when we read the data on 8 October 2026.
- 1
What URLhaus lists
Eleven JPG files on res.cloudinary.com, all under image/upload, named img_ followed by six digits and sometimes a short random suffix. They were added between 9 and 24 September 2026, all with the threat label malware_download and the reporter abuse_ch. Every one is marked offline.
- 2
What the tags mean
stego is short for steganography: code hidden inside another file, here a picture. RemcosRAT is a remote access trojan, a program that lets a stranger control a Windows PC. rat means the same. PureLogsStealer is a password and wallet stealer. One file carries no tag at all.
- 3
What we could not confirm
We did not download the pictures, so we cannot tell you what is inside them or where the trojans report to. We do not know which email or program made a victim's PC ask for these pictures. That first step is not visible from the server side.
- 4
What this means for you
If you only saw res.cloudinary.com in a log or a blocked request, nothing is proven: almost every request to it is a normal website loading a normal picture. The risk is for a PC where a loader already ran and fetched one of these files.
- Kind of threat
- Malware hidden in JPG pictures on a legitimate image service: seven tagged RemcosRAT, one PureLogsStealer
- The service
- Cloudinary, an image and video hosting service. cloudinary.com was registered on 24 May 2011 through GoDaddy.com, LLC (RDAP, read 8 October 2026)
- Where the files were
- hxxps://res.cloudinary[.]com/<account>/image/upload/v<upload time>/img_NNNNNN.jpg in six accounts: leowxn6s, slwv2ypq, tll9jvom, te9euryt, ohmsggn3 and rpfuztjy
- URLhaus entries
- 11 file addresses, added 9 to 24 September 2026; all 11 offline on 8 October 2026
- Delivery trick
- Steganography: code hidden in a picture so the download looks like an image. A loader already on the PC fetches it
- Platform
- Windows. MITRE lists Remcos as Windows only. Nothing we read says these pictures affect Mac, iPhone or Android
What Cloudinary virus (malware hidden in pictures on res.cloudinary.com) does on an infected PC
What we checked on 8 October 2026, and what we could not
We sent one plain request from our server to https://res.cloudinary.com/ on 8 October 2026, with no browser and no clicks. It answered HTTP 404 from a server that names itself Cloudinary. That is normal: the bare address has no page, only the pictures under it do. It does not test the eleven reported files, and a quiet answer clears nothing.
Our check, 8 October 2026
- The service answers normallyHTTP 404 at the bare address, server header Cloudinary, no redirect, no notification request.
- Domain registrationcloudinary.com, registered 24 May 2011 through GoDaddy.com, LLC, with delete, renew, transfer and update locks. That is what a real company's domain looks like.
- URLhaus listingEleven JPG files tagged RemcosRAT, PureLogsStealer, rat and stego, added 9 to 24 September 2026.
- Are the files still served?All eleven are marked offline. That usually means the account or the file was removed.
- What we did not doWe did not download the pictures or run anything. New accounts with new pictures can appear at any time.
Safe service, abused by some account holders res.cloudinary.com is a legitimate image service used by many websites. The danger is in specific pictures that criminals upload and that a loader on an infected PC fetches. Judge the full link and the program that asked for it, not the domain.
The eleven reports, in order
Every Cloudinary link carries a version number that the documentation says is the timestamp of the upload. Comparing it with the URLhaus date shows how fast the pictures were found. Times are UTC.
24 May 2011
cloudinary.com is registered
RDAP shows the domain registered on 24 May 2011 through GoDaddy.com, LLC.
9 September 2026
Two pictures in the account leowxn6s
Uploaded just after midnight UTC and added by abuse_ch at about 08:13 and 08:14 the same day. Both tagged RemcosRAT and rat, one also stego.
14 September 2026
Five pictures in two accounts
Four pictures in slwv2ypq, uploaded between about 02:02 and 08:01 UTC; two tagged RemcosRAT and stego, two only stego. One picture in tll9jvom, uploaded at about 05:54 UTC and tagged PureLogsStealer and stego.

The eleven URLhaus reports for res.cloudinary.com, September 2026, in six accounts. 15 September 2026
One picture with no tag
In the account te9euryt, uploaded at about 10:52 UTC and added at about 15:38 UTC. URLhaus gives it no family tag.
22 September 2026
Two pictures in ohmsggn3
Uploaded on 21 and 22 September and added the same afternoon or the next day. Both tagged RemcosRAT, rat and stego.
24 September 2026
The last one, in rpfuztjy
Uploaded at about 05:19 UTC, added at about 13:47 UTC, tagged RemcosRAT, rat and stego.
8 October 2026
All offline, and our check
All eleven entries are offline. Our plain request to the bare address gets Cloudinary's normal 404.
Our reading of the pattern: six new accounts in two weeks, each used for one to four pictures and each found within hours, fits an operator who opens fresh free accounts as old ones are closed. That is an inference from the names and dates, not something a report states.
How criminals use Cloudinary, and why a picture is their choice
A picture that hides code cannot hurt you by being looked at. It works only when a loader that is already running reads the hidden part and starts it. Cloudinary is chosen because it is free to start, fast and trusted.

- 1
An account makes a public address
Cloudinary's documentation gives the delivery pattern res.cloudinary.com/<cloud_name>/<asset_type>/<delivery_type>/<version>/<public_id>.<extension>. The cloud name is the account, and the version is the upload timestamp. Any uploaded picture gets such a public link at once.
- 2
A loader asks for the picture
Seqrite (17 March 2025) described a phishing Excel file that leads to a script which downloads a JPG with base64 text between the markers <<BASE64 START>> and <<BASE64 END>>, decodes a loader from it and then injects Remcos into a trusted Windows program such as caspol.exe or msbuild.exe.
- 3
The payload runs in memory
K7 Labs (22 June 2026, updated 30 July) described a Remcos chain from an archive attached to a phishing email, with stages hidden in a .NET Bitmap and loaded in memory, ending in Remcos running inside the default browser process.
- 4
It breaks Cloudinary's rules
Cloudinary's Acceptable Use Policy, last updated 12 September 2024, forbids using the service to transmit malware or to upload content with viruses, Trojans or other harmful code, and asks people to report abuse.
What Remcos and PureLogs are
Seven of the eleven pictures were tagged RemcosRAT and one PureLogsStealer. Both are sold to criminals and both target Windows.
| Question | What the sources say | Source |
|---|---|---|
| What is Remcos? | A closed source tool marketed as remote control and surveillance software by a company called Breaking Security, seen in many malware campaigns | MITRE ATT&CK S0332, modified 23 April 2026 |
| What can Remcos do? | Log keys, take screenshots, use the webcam and microphone, read the clipboard, move and delete files | Microsoft Backdoor:Win32/Remcos; MITRE |
| How does Remcos stay? | A registry Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run; K7 Labs also saw winlogon and userinit entries and a hidden copy in AppData\Roaming | MITRE; K7 Labs |
| What is PureLogs? | A stealer that takes browser data, saved passwords, crypto wallets, files, clipboard contents, screenshots and keystrokes, often delivered by the PureCrypter loader | ANY.RUN malware trends |
| Which system? | Windows. MITRE lists Remcos for Windows only | MITRE |
What Cloudinary virus (malware hidden in pictures on res.cloudinary.com) can steal or download
What these trojans can take from a Windows PC
A remote access trojan gives a stranger a seat at your computer. The list is what the sources say is possible, not what one build does automatically.
Reported as possible
- Every key you type
- Screenshots
- Webcam pictures
- Microphone audio
- Clipboard contents
- Saved browser passwords and cookies
- Crypto wallets
- Files moved or deleted
| Data | Detail | Source |
|---|---|---|
| Keystrokes and screen | Keylogging and automated screenshots | MITRE; Microsoft |
| Camera and sound | Webcam pictures and microphone recording | MITRE; Microsoft |
| Browser logins | Chrome logins and cookies, Firefox credentials | K7 Labs |
| Wallets and files | PureLogs takes wallets and files by folder and extension | ANY.RUN |
What this can cost you
Seeing the address costs nothing. These risks apply to a Windows PC where a loader fetched one of these pictures and the trojan ran.
- High
Passwords and accounts
A keylogger records every password you type, including new ones set on the same PC.
- High
Someone using your PC live
The controller can come back, watch the screen and act while you are logged in.
- High
Crypto and banking
Wallet theft cannot be reversed, and a banking session opened on the PC can be watched.
- Medium
Private files, camera and microphone
Documents can be taken, and the camera and microphone can be used.
- Low
Nothing, if you only saw the name
A request to res.cloudinary.com in a log is almost always a normal website picture.
How to check the PC for Cloudinary virus (malware hidden in pictures on res.cloudinary.com)
How to tell a bad Cloudinary link from a normal one
The domain tells you nothing either way. Look at who asked for the picture and what the link looks like.
| Sign | Normal use | Abuse in the reports |
|---|---|---|
| Who asks for it | Your browser, while showing a shop or news page | A script, PowerShell, wscript.exe or an unknown program |
| The account name | Often the brand's own name | Eight random letters and digits, such as slwv2ypq |
| The file name | A product or article name, often with resize options in the path | img_ plus six digits, sometimes with a random suffix |
| When you see it | While a picture appears on a page | In a firewall or antivirus alert with no page open |
| What follows | Nothing | A new startup entry, a trusted program using the network, a Defender alert |
Check your PC before you delete anything
The question that matters: did a program on this PC, not your browser, ask for one of these pictures, or did you open an unexpected attachment? If not, and you only saw the address in a log, you can stop here. If yes, or you are not sure, do these checks. None deletes anything.
Use another device for banking, email and work until you finish.
- 1
Disconnect first
Turn off Wi-Fi or unplug the cable. A remote access trojan needs the connection to be used.
- 2
Look at Protection history
Open Windows Security > Virus & threat protection > Protection history. A detection named Backdoor:Win32/Remcos or one naming PureLogs is a firm sign.
- 3
Check the Run key
Open Registry Editor and go to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run. MITRE says Remcos adds itself there. Note any entry that points into AppData\Roaming with a random name.
- 4
Check Startup apps and Task Manager
Open Settings > Apps > Startup, then Task Manager. A trusted program such as msbuild.exe or caspol.exe running with no reason is worth a note, since Seqrite saw Remcos hidden in them.
- 5
Look at recent attachments
Think back to an archive, an Excel file or an invoice you opened around the time of the alert. That is the likely start.
How to remove Cloudinary virus (malware hidden in pictures on res.cloudinary.com)
How to remove Cloudinary virus
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:
- a task that starts a file in
%AppData%or%Temp% - runs
powershellwith a long encoded line - opens a web address belongs to Cloudinary virus or a similar program
Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
- a task that starts a file in
Step 2: Remove it from startup
Whatever Cloudinary virus installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.
Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.
Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through
%LocalAppData%,%AppData%, %ProgramData% and the two Program Files folders.Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold
.exe,.dll, .js or .ps1 files are the strongest sign.Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.
Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
If you use a Mac, an iPhone or an Android phone
The tags and the sources describe Windows. Cloudinary pictures load on every device, but only a Windows loader can use the hidden code in these files.
| Your device | What we know | What to do |
|---|---|---|
| Mac | MITRE lists Remcos for Windows only | Nothing to remove for this threat. Do not follow the Windows steps on a Mac |
| iPhone or iPad | No source describes these files on iOS | Nothing to remove. Pictures from Cloudinary in apps are normal |
| Android | No source mentions them on Android | Nothing to remove for this threat |
After removal: passwords, accounts and prevention
Your passwords after Cloudinary virus
Removing Cloudinary virus does not undo what it may already have sent out while the PC showed A script, loader or program that downloads JPG pictures from res.cloudinary.com in the list of installed apps. Treat saved browser passwords and logged-in sessions on this PC as known to the attacker.
From another device, change the e-mail password first and end all its sessions. Then do the same for the bank, PayPal, Microsoft, Google and Apple accounts. Stolen session cookies keep working after a password change until you sign out everywhere.
Move crypto to a new wallet created on a clean device. A step-by-step order for every kind of account is in our guide to account security after an infection.
After a clean PC: protect what was taken
Cleaning the PC does not undo what was sent. Do the account steps from another device first.

- 1
Change passwords from a clean device
Start with email, then bank, work, cloud storage and crypto. Anything typed on the PC while the trojan ran is known.
- 2
Sign out every session
Use each account's option to sign out of all devices, and turn on two step sign in.
- 3
Run Microsoft Defender Offline
Open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Antivirus (offline scan) and Scan now. The PC restarts and scans before Windows loads; results are in Protection history.
- 4
Reset Windows if you are not sure
A remote access trojan may have added more programs. Settings > System > Recovery > Reset this PC with Remove everything is the sure way.
Keep a PC out of this kind of chain
The picture is the late part of the chain. Every report starts with a file a person opened.
Do
- Treat an unexpected archive, invoice or Excel file that asks you to enable content as an attack.
- Show file endings in File Explorer so a program posing as a document is visible.
- Keep Windows and Microsoft Defender updated.
- Use a password manager and two step sign in.
- Report a bad picture link to Cloudinary through its support channel, citing its Acceptable Use Policy.
Don't
- Do not block the whole of res.cloudinary.com: many shops and sites will lose their pictures.
- Do not open attachments you did not expect, even from a known name.
- Do not change passwords on the PC you suspect.
- Do not treat a clean quick scan as proof.
Questions about Cloudinary virus (malware hidden in pictures on res.cloudinary.com)
Is Cloudinary a virus?
No. Cloudinary is a legitimate image and video hosting service used by many shops, news sites and apps, and its domain has been registered since 2011.
It shows up in malware reports because criminals open free accounts and upload pictures that hide code. The service is safe; some uploaded files are not. Its own rules forbid malware.
Why did my antivirus block res.cloudinary.com?
Most likely it blocked one picture address, not the whole service. Look at the full link and at the program named in the alert.
If your browser was showing a normal page, it may be a false alarm on that file. If the program was a script, PowerShell or something you do not know, treat the PC as possibly infected.
What files were reported on Cloudinary?
URLhaus lists eleven JPG pictures on res.cloudinary.com, added between 9 and 24 September 2026 in six accounts. Seven were tagged RemcosRAT, one PureLogsStealer, nine stego and one had no tag.
All eleven were offline on 8 October 2026. We did not download them, so we cannot show what is inside.
Can a picture from Cloudinary infect me if I just look at it?
No source we read says so. The hidden code in these pictures is only data until a loader that is already running on the PC reads it and starts it.
Your browser shows the picture and ignores the rest. The danger is the attachment or program that started the loader in the first place.
What is Remcos?
Remcos is a closed source tool sold as remote control and surveillance software and widely used by criminals. Microsoft detects it as Backdoor:Win32/Remcos and says it collects keystrokes, webcam images, screenshots and passwords. MITRE says it stays by adding itself to the current user's Run registry key, and lists it as a Windows tool.
What is PureLogs Stealer?
PureLogs is a stealer of the Pure family of malware tools. ANY.RUN says it takes browsing history, cookies and autofill data, saved passwords, crypto wallets and files, and is often delivered by the PureCrypter loader.
One of the eleven Cloudinary pictures was tagged with it. It targets Windows PCs: ANY.RUN describes Run key persistence and PowerShell, and its samples ran on Windows 10. Phishing emails and fake downloads are the usual way in.
How do I remove Remcos from a Windows PC?
Disconnect the PC, change your passwords from another device, then run Microsoft Defender Offline from Windows Security, Scan options. Look in the Run registry key and Startup apps for entries you do not know. If you are unsure that everything is gone, reset Windows with Remove everything, because a remote access trojan can add more programs.
Can I block Cloudinary to be safe?
Blocking res.cloudinary.com will break pictures on many shops and websites. It also does not remove a loader that is already on a PC.
A better step is to keep unexpected attachments closed, keep Defender updated, and in a company to watch which programs, other than browsers, download pictures. A script or msbuild.exe fetching a JPG is a strong warning sign.
How do I report a malicious Cloudinary picture?
Cloudinary's Acceptable Use Policy forbids malware and asks people to report abuse, though it names no address; use its support contact and give the full link. You can also submit the link to URLhaus at abuse.ch, which shares it with security vendors and network operators. Include the date and the program that asked for the picture if you know it.
Will Fortect remove Cloudinary virus?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For Cloudinary virus, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- URLhaus (abuse.ch): eleven entries for res.cloudinary.com, 9 to 24 September 2026, from our job data (read October 8, 2026)
- Microsoft Security Intelligence: Backdoor:Win32/Remcos (updated 25 September 2023) (read October 8, 2026)
- MITRE ATT&CK: Remcos, S0332 (modified 23 April 2026) (read October 8, 2026)
- K7 Labs: A multi stage steganographic loader campaign deploying diverse payloads globally (22 June 2026, updated 30 July 2026) (read October 8, 2026)
- Seqrite: New steganographic campaign distributing multiple malware (17 March 2025) (read October 8, 2026)
- ANY.RUN malware trends: PureLogs (read October 8, 2026)
- Cloudinary Acceptable Use Policy (last updated 12 September 2024) (read October 8, 2026)
- Cloudinary documentation: Image transformations, delivery URL structure (read October 8, 2026)
- Microsoft Support: Help protect my PC with Microsoft Defender Offline (read October 8, 2026)