Virtual Invasion: SolarWinds WHD Exploited to Host Hidden QEMU VMs
ID: eac09bb5-54c3-587e-98de-bcb01809e3fa
STIX ID: report--eac09bb5-54c3-587e-98de-bcb01809e3fa
Feed Name: securityonline.info
Microsoft Defender researchers observed a December 2025 intrusion campaign exploiting internet-facing SolarWinds Web Help Desk instances to gain initial access, deploy QEMU virtual machines launched as SYSTEM for covert persistent access and port-forwarded SSH, and steal credentials via DLL sideloading of wab.exe (sspicli.dll) enabling LSASS memory access and at least one DCSync; several CVEs are possible entry points and organizations are urged to patch, remove public administrative access, and hunt for RMM artifacts and QEMU persistence indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
