logo

Velociraptor WSUS Exploitation, Pt. I: WSUS-Up?

ID: 79ce8b73-2242-5f23-9fbb-06583c059a72

STIX ID: report--79ce8b73-2242-5f23-9fbb-06583c059a72

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-11-20

Date Updated: 2026-04-28

...
...

Huntress observed threat actors exploiting a WSUS deserialization RCE (CVE-2025-59287) to install Velociraptor from a malicious MSI hosted on s3.wasabisys.com; Velociraptor was configured to communicate with update.githubtestbak.workers.dev and was used to execute base64-encoded PowerShell discovery commands. The incident was contained by Huntress SOC; the report highlights this as part of a broader trend of abusing legitimate DFIR tools and provides IOCs and event-log evidence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.