Velociraptor WSUS Exploitation, Pt. I: WSUS-Up?
ID: 79ce8b73-2242-5f23-9fbb-06583c059a72
STIX ID: report--79ce8b73-2242-5f23-9fbb-06583c059a72
Feed Name: Huntress Blog
Threat Score
Huntress observed threat actors exploiting a WSUS deserialization RCE (CVE-2025-59287) to install Velociraptor from a malicious MSI hosted on s3.wasabisys.com; Velociraptor was configured to communicate with update.githubtestbak.workers.dev and was used to execute base64-encoded PowerShell discovery commands. The incident was contained by Huntress SOC; the report highlights this as part of a broader trend of abusing legitimate DFIR tools and provides IOCs and event-log evidence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
