res.cloudinary.com in a browser or security log does not, by itself, establish that a Windows PC is infected. Cloudinary’s documentation identifies that hostname as its default shared content-delivery domain: different customers’ images can arrive from the same address. The important distinction is between a legitimate hosting service and particular files hosted on it.An October 8 report from 2-Spyware examines eleven Cloudinary-hosted URLs associated with malware reports. URLhaus corroborates those eleven entries within the specified September 9–24, 2026 window, including tags for RemcosRAT, PureLogsStealer and suspected steganography. This is a reason to investigate specific alerts—not to declare every Cloudinary image dangerous.
What the eleven reports establish
The relevant URLhaus entries span six distinct cloud-name paths and are attributed to the reporter abuse_ch. Their overlapping labels include:
- Seven entries tagged
RemcosRAT. - One entry tagged
PureLogsStealer. - Nine entries tagged
stego. - One entry without a malware-family or technique tag.
All eleven were displayed as Offline in the listing inspected for this article. That agrees with 2-Spyware’s reported October 8 observation, but it is a point-in-time status—not proof that a computer which previously fetched a file is clean. The eleven-entry count applies to September 9–24; URLhaus also lists earlier activity on the hostname.
2-Spyware describes the objects as JPG images containing concealed malware data, while acknowledging that its authors did not download them or identify the initial program that fetched them. The accessible URLhaus table corroborates the labels, but does not independently demonstrate the hidden contents or establish an infection chain for a particular victim. Database tags are useful leads, not a substitute for examining endpoint evidence.
The takeaway: these are reports about specific hosted objects, not evidence that Cloudinary itself has become malware.
Why the initiating program matters
Cloudinary documents a shared delivery structure containing a customer’s cloud name and asset path. Blocking the entire hostname would therefore affect unrelated customers’ media. As an operational recommendation derived from that structure, administrators should prefer precise URL or other supported indicator controls where possible, rather than treating the shared domain as a universal threat indicator.
The investigation should distinguish three different events: a request was attempted, a file was downloaded, and malicious code executed. Those are not interchangeable conclusions. URLhaus reports a hosting location; it does not establish what happened on your PC.
For an alert involving one of these URLs, preserve the full address, timestamp, detection name and initiating process. Determine whether protection blocked the request and whether endpoint records show subsequent execution. This is investigative guidance based on the evidence gap—not a finding that every script fetching an image is malicious.
The Remcos label warrants attention. Microsoft’s Security Intelligence description says Remcos can control an infected system and collect keystrokes, screenshots, webcam images and passwords. Those are documented family capabilities, not confirmation that any particular Cloudinary request caused those actions.
Checking and cleaning a Windows PC
There is no separate “Cloudinary virus” component to uninstall merely because the hostname appears in a log. The response should target any detected loader, backdoor or other malware.
For a personal PC using Microsoft Defender Antivirus, Microsoft documents the following checks for Windows 11 and Windows 10:
- Open Windows Security > Virus & threat protection and review Protection history.
- Under Protection updates, select Check for updates.
- Open Scan options, select Full scan, and start the scan.
- Follow Windows Security’s remediation prompts for detected threats; do not restore or allow an unfamiliar detection simply to silence the alert.
Microsoft specifically recommends updated antivirus definitions and a full scan for Remcos, noting that infections can leave files and system changes behind.
When to use Microsoft Defender Offline
For suspected persistent malware on an eligible system, save your work, then open Windows Security > Virus & threat protection > Scan options. Select Microsoft Defender Antivirus (offline scan) and Scan now. The computer restarts, scans in the Windows Recovery Environment, and returns to Windows. Review Protection history afterward.
Important prerequisites and failure points apply:
- Microsoft lists support for x64 Windows 11 and x86/x64 Windows 10, but excludes ARM Windows and Windows Server.
- Defender must be the primary antivirus, with current updates; local administrator privileges are required.
- Windows Recovery Environment must be enabled.
- Microsoft advises suspending system-drive BitLocker protection before scanning to avoid a recovery-key prompt. Managed-device users should involve IT.
If the offline scan does nothing, Microsoft identifies disabled recovery functionality as one possible cause. An administrator can check it with reagentc /info and, if disabled, enable it with reagentc /enable from an elevated command prompt.
A completed scan and reviewed results confirm that the procedure ran; they do not prove that credentials were never exposed. Where Remcos execution is confirmed, account protection deserves attention alongside device cleanup because password collection is among its documented capabilities.
Keep the response proportional
The useful lesson is neither “trust every image” nor “block Cloudinary.” It is to assess the specific URL, requesting process and endpoint behavior together. Cloudinary’s shared-domain design explains why hostname-only judgments are too broad, while the URLhaus reports explain why particular hosted files can still deserve investigation. The address is a clue—not a verdict.
References
- Cloudinary Virus: Is res.cloudinary.com Safe? Removal - 2-Spyware 2-Spyware · 2026-10-08T09:12:48.376000+00:00
- URLhaus | res.cloudinary.com urlhaus.abuse.ch
- Virus and Threat Protection in the Windows Security App - Microsoft Support support.microsoft.com