logo

Velociraptor Misuse, Pt. II: The Eye of the Storm

ID: 10477b3d-c328-5ef8-8f20-3ec495a63636

STIX ID: report--10477b3d-c328-5ef8-8f20-3ec495a63636

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-12-03

Date Updated: 2026-04-28

...
...

## Executive summary Huntress investigated three related incidents where attackers exploited SharePoint (ToolShell) and previously WSUS vulnerabilities to install Velociraptor as a C2/remote execution platform, use legitimate tools (VS Code, Cloudflare tunnels, OpenSSH) to evade detection, and in one case deploy Warlock ransomware; the report provides timelines, forensic artifacts, IOCs, and remediation notes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.