logo

Virtual Invasion: SolarWinds WHD Exploited to Host Hidden QEMU VMs

ID: eac09bb5-54c3-587e-98de-bcb01809e3fa

STIX ID: report--eac09bb5-54c3-587e-98de-bcb01809e3fa

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-02-10

Date Updated: 2026-04-23

Author: Ddos

...
...

Microsoft Defender researchers observed a December 2025 intrusion campaign exploiting internet-facing SolarWinds Web Help Desk instances to gain initial access, deploy QEMU virtual machines launched as SYSTEM for covert persistent access and port-forwarded SSH, and steal credentials via DLL sideloading of wab.exe (sspicli.dll) enabling LSASS memory access and at least one DCSync; several CVEs are possible entry points and organizations are urged to patch, remove public administrative access, and hunt for RMM artifacts and QEMU persistence indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.