logo

Someone's attacking SolarWinds WHD to steal high‑privilege credentials - but we don't know who or how

ID: 2fbf8a56-49cc-57aa-8323-d664dc009ea4

STIX ID: report--2fbf8a56-49cc-57aa-8323-d664dc009ea4

Feed Name: The Register (Security)

Threat Score
82/100

Date Published: 2026-02-09

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Microsoft researchers observed attackers exploit buggy SolarWinds Web Help Desk instances in December 2025 to gain remote code execution and move laterally, using techniques such as BITS-based payload delivery, installation of ManageEngine RMM for persistence, reverse SSH/RDP, DLL sideloading to access LSASS memory and credential theft (including DCSync), and even creating a SYSTEM-level scheduled task launching a QEMU VM to hide activity; the exact CVE used is undetermined among several critical WHD flaws (CVE-2025-40551, CVE-2025-40536, CVE-2025-26399).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.