logo

Analysis of active exploitation of SolarWinds Web Help Desk

ID: 3992c6bc-2187-5f53-94cf-eadf64497fe8

STIX ID: report--3992c6bc-2187-5f53-94cf-eadf64497fe8

Feed Name: Microsoft Security

Threat Score
85/100

Date Published: 2026-02-07

Date Updated: 2026-04-28

Author: Microsoft Defender Security Research Team

...
...

Microsoft Defender observed an active campaign exploiting internet-exposed SolarWinds Web Help Desk (WHD) instances to achieve unauthenticated RCE, deploy payloads (including abused RMM tooling), and perform lateral movement and credential theft (LSASS access and DCSync). The report provides technical details, detections, KQL hunting queries, and mitigation guidance (patching WHD, removing unauthorized RMM artifacts, rotating credentials, and isolating hosts).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.