Hackers exploit SolarWinds WHD flaws to deploy DFIR tool in attacks
ID: 10bda181-c4f8-5eb0-a0ab-cd9fa9644602
STIX ID: report--10bda181-c4f8-5eb0-a0ab-cd9fa9644602
Feed Name: Bleeping Computer
Researchers observed an active campaign (starting mid-January) exploiting critical, internet‑exposed SolarWinds Web Help Desk RCE vulnerabilities to compromise at least three organizations. The attackers installed Zoho ManageEngine Assist for hands‑on access, deployed Velociraptor as a C2 mechanism via Cloudflare Workers, used Cloudflared tunnels for persistence and redundancy, disabled Windows Defender/Firewall, and employed scheduled tasks and SSH backdoors; Huntress published Sigma rules and IoCs and recommended upgrading SolarWinds WHD and removing public access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
