Hackers Leverage Velociraptor DFIR Tool for Stealthy C2 & Ransomware Delivery
ID: 2a8d9b58-8b50-53c8-b892-ba59eaf14d80
STIX ID: report--2a8d9b58-8b50-53c8-b892-ba59eaf14d80
Feed Name: cybersecurityNews.com
Threat Score
Attackers exploited SharePoint and WSUS infrastructure vulnerabilities in late 2025 to install Velociraptor as a stealthy C2/persistent service via web shells and msiexec, leveraged Cloudflare tunnels and signed binaries to evade detection, and in confirmed cases deployed Warlock ransomware; Huntress investigators linked artifacts (including hostname DESKTOP-C1N9M) to the financially motivated cluster Storm-2603.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
