Active Exploitation of SolarWinds Web Help Desk (CVE-2025-26399)
ID: 8fa0f1b1-2b29-55d9-8890-42298cf326d1
STIX ID: report--8fa0f1b1-2b29-55d9-8890-42298cf326d1
Feed Name: Huntress Blog
Huntress observed active exploitation of SolarWinds Web Help Desk vulnerabilities leading to rapid post-exploitation actions across multiple customers: attackers achieved RCE via WHD, silently installed remote MSI payloads (Zoho/ManageEngine RMM, Velociraptor), established redundant C2 (Cloudflared, Cloudflare Workers), disabled Windows security controls, implemented QEMU-based SSH persistence, and exfiltrated system information to an attacker-controlled Elastic Cloud instance; the report provides IOCs, detection guidance, and recommended WHD updates and access restrictions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
