Someone's attacking SolarWinds WHD to steal high‑privilege credentials - but we don't know who or how
ID: 2fbf8a56-49cc-57aa-8323-d664dc009ea4
STIX ID: report--2fbf8a56-49cc-57aa-8323-d664dc009ea4
Feed Name: The Register (Security)
Microsoft researchers observed attackers exploit buggy SolarWinds Web Help Desk instances in December 2025 to gain remote code execution and move laterally, using techniques such as BITS-based payload delivery, installation of ManageEngine RMM for persistence, reverse SSH/RDP, DLL sideloading to access LSASS memory and credential theft (including DCSync), and even creating a SYSTEM-level scheduled task launching a QEMU VM to hide activity; the exact CVE used is undetermined among several critical WHD flaws (CVE-2025-40551, CVE-2025-40536, CVE-2025-26399).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
