logo

Hackers exploit SolarWinds WHD flaws to deploy DFIR tool in attacks

ID: 10bda181-c4f8-5eb0-a0ab-cd9fa9644602

STIX ID: report--10bda181-c4f8-5eb0-a0ab-cd9fa9644602

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-02-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers observed an active campaign (starting mid-January) exploiting critical, internet‑exposed SolarWinds Web Help Desk RCE vulnerabilities to compromise at least three organizations. The attackers installed Zoho ManageEngine Assist for hands‑on access, deployed Velociraptor as a C2 mechanism via Cloudflare Workers, used Cloudflared tunnels for persistence and redundancy, disabled Windows Defender/Firewall, and employed scheduled tasks and SSH backdoors; Huntress published Sigma rules and IoCs and recommended upgrading SolarWinds WHD and removing public access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.