logo

Attackers abuse SolarWinds Web Help Desk to install Zoho agents and Velociraptor

ID: 8cfdd0e3-178e-52e3-b4ab-207d7d8bf573

STIX ID: report--8cfdd0e3-178e-52e3-b4ab-207d7d8bf573

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-02-09

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Active in-the-wild exploitation of unpatched SolarWinds Web Help Desk (WHD) vulnerabilities (including CVE-2025-26399 and CVE-2025-40551) enabled attackers to remotely execute code, silently install Zoho ManageEngine RMM/Assist agents for persistent access (registered to a Proton Mail address), and deploy Velociraptor configured to use Cloudflare Workers as C2 with Cloudflared tunnels and failover mechanisms; post-exploitation activity included domain enumeration, disabling Defender and the Windows Firewall, creating scheduled tasks for persistence (abusing QEMU), and sending system telemetry to an attacker-controlled Elastic Cloud/Kibana instance—Huntress published mitigations and IoCs and recommends immediate WHD updates, restricting admin access, credential resets, and hunting for unauthorized remote access tools and encoded PowerShell/MSI installations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.