Chinese Hackers Use Velociraptor IR Tool in Ransomware Attacks
ID: a47d596c-3d82-532e-920c-2a878da3864b
STIX ID: report--a47d596c-3d82-532e-920c-2a878da3864b
Feed Name: Dark Reading
Cisco Talos and Sophos researchers observed China-based Storm-2603 (aka Gold Salem/Warlock) abusing the open-source DFIR tool Velociraptor to establish stealthy persistent access and deploy multiple ransomware families (Warlock, LockBit, Babuk) after compromising SharePoint and VMware ESXi servers. The actors installed an outdated Velociraptor version vulnerable to CVE-2025-6264, used Msiexec for installation, and leveraged legitimate tooling and cloud-hosted C2 domains to evade detection; vendors have published detections and mitigation guidance to identify unauthorized Velociraptor instances and related artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
