A lot of hacking groups, terror organizations and other malicious actors have been using cloud flare for a while without them doing shit about it.
It's their business model. More DDoS means more cloudflare customers, yaaay.
A guy ran a DNS and logged all the suspicious domains linking to cloud flare (e.g. cname entries etc): he eventually gave up cause he was sued into oblivion (he was a Swiss guy operating from Switzerland).
http://web.archive.org/web/20210826102143/http://www.crimefl...
And this kinda speaks for itself:
http://web.archive.org/web/20210826102230/http://www.crimefl...