Attackers abuse SolarWinds Web Help Desk to install Zoho agents and Velociraptor
ID: 8cfdd0e3-178e-52e3-b4ab-207d7d8bf573
STIX ID: report--8cfdd0e3-178e-52e3-b4ab-207d7d8bf573
Feed Name: Security Affairs
Active in-the-wild exploitation of unpatched SolarWinds Web Help Desk (WHD) vulnerabilities (including CVE-2025-26399 and CVE-2025-40551) enabled attackers to remotely execute code, silently install Zoho ManageEngine RMM/Assist agents for persistent access (registered to a Proton Mail address), and deploy Velociraptor configured to use Cloudflare Workers as C2 with Cloudflared tunnels and failover mechanisms; post-exploitation activity included domain enumeration, disabling Defender and the Windows Firewall, creating scheduled tasks for persistence (abusing QEMU), and sending system telemetry to an attacker-controlled Elastic Cloud/Kibana instance—Huntress published mitigations and IoCs and recommends immediate WHD updates, restricting admin access, credential resets, and hunting for unauthorized remote access tools and encoded PowerShell/MSI installations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
