logo

Active Exploitation of SolarWinds Web Help Desk RCE Used to Drop Custom Malware

ID: c22be909-97aa-54d0-bbe1-4e091d51fca4

STIX ID: report--c22be909-97aa-54d0-bbe1-4e091d51fca4

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-02-09

Date Updated: 2026-04-22

Author: Divya

...
...

Researchers observed active exploitation of critical SolarWinds Web Help Desk RCE vulnerabilities (CVE-2025-40551 and CVE-2025-26399) beginning Feb 7, 2026, where attackers use the WHD service to spawn Java processes that install a Zoho ManageEngine RMM agent as a persistent backdoor, deploy a weaponized Velociraptor for C2 via a Cloudflare Worker domain, disable Defender, exfiltrate data to an attacker-controlled Elastic Cloud instance, and rotate infrastructure using a dynamic DNS failover mechanism; the report includes detailed IOCs and recommends immediate patching of versions earlier than 12.8.7 HF1.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.