No Malware. No Alerts. 216 Servers Gone.
ID: e974e9f1-8b7c-5a6c-885d-98a817b71901
STIX ID: report--e974e9f1-8b7c-5a6c-885d-98a817b71901
Feed Name: NoHackie
Security researchers uncovered a large-scale campaign where threat actors exploited SolarWinds Web Help Desk deserialization RCE (CVE-2025-26399 and related bypasses) to compromise at least 216 hosts across 34 Active Directory domains, deploy legitimate management/DFIR tools and QEMU-based persistence, and exfiltrate structured system metadata to a disposable Elastic Cloud SIEM trial which they used to triage and prioritize further intrusion; the report provides technical details, IOCs (IPs, disposable email patterns, Kibana artifacts), and pragmatic detection and remediation guidance including immediate patching to WHD 2026.1, hunting for unexpected QEMU processes, and monitoring anomalous API key usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
