logo

Hackers now use Velociraptor DFIR tool in ransomware attacks

ID: 127543db-7c70-55a8-ab9d-4669c6ef952e

STIX ID: report--127543db-7c70-55a8-ab9d-4669c6ef952e

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-10-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Cisco Talos and other vendors observed a China-linked actor tracked as Storm-2603 abusing an outdated Velociraptor DFIR build (v0.73.4.0) subject to CVE-2025-6264 to establish persistent, privileged access and deploy LockBit and Babuk ransomware across Windows and VMware ESXi hosts; the campaign included account creation synced to Entra ID, remote execution (Impacket-style commands), disabling Defender via AD GPOs, scheduled tasks, a fileless PowerShell encryptor with per-run AES keys, and pre-encryption data exfiltration for double extortion, with IoCs published by researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.