logo

Exploiting Velociraptor – Cyberattackers Use Incident Response Tool for Remote Access

ID: 40b7bf66-5bd9-5d80-be3e-5d8b0422c222

STIX ID: report--40b7bf66-5bd9-5d80-be3e-5d8b0422c222

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-08-28

Date Updated: 2026-05-08

Author: Priya

...
...

Sophos CTU uncovered an attack campaign that abused legitimate DFIR and development tools—Velociraptor and Visual Studio Code tunneling—to create a covert C2 channel and persistent access. Attackers used msiexec to download staged installers (v2.msi, sc.msi) from Cloudflare Workers domains (files.qaubctgg.workers.dev, velo.qaubctgg.workers.dev), executed encoded PowerShell to enable tunneling, and prepared for likely ransomware deployment; detection via Taegis™ and rapid isolation prevented further spread. The report includes observed malware family names and IOCs and emphasizes treating unexpected Velociraptor or VS Code tunneling activity as high-risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.