SolarWinds Web Help Desk Exploitation - February 2026
ID: d3b20c60-bc1b-5a87-aec6-309a31f630ea
STIX ID: report--d3b20c60-bc1b-5a87-aec6-309a31f630ea
Feed Name: Elastic Security Labs
This report describes active exploitation of SolarWinds Web Help Desk (WHD) servers (first observed Dec 2025, reported Feb 6, 2026) that led to multi-stage intrusions: attackers reportedly leveraged one or more WHD vulnerabilities (several CVEs cited), established interactive shells, installed RMM agents and tools like Velociraptor and Cloudflared, created a QEMU-based persistent access tunnel, and performed credential dumping including extraction of NTDS.dit; the report maps observed behaviors to MITRE ATT&CK, lists Elastic Security detections/preventions, and provides patching, credential rotation, and investigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
