logo

Hackers Leverage Velociraptor DFIR Tool for Stealthy C2 & Ransomware Delivery

ID: 2a8d9b58-8b50-53c8-b892-ba59eaf14d80

STIX ID: report--2a8d9b58-8b50-53c8-b892-ba59eaf14d80

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Attackers exploited SharePoint and WSUS infrastructure vulnerabilities in late 2025 to install Velociraptor as a stealthy C2/persistent service via web shells and msiexec, leveraged Cloudflare tunnels and signed binaries to evade detection, and in confirmed cases deployed Warlock ransomware; Huntress investigators linked artifacts (including hostname DESKTOP-C1N9M) to the financially motivated cluster Storm-2603.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.