Velociraptor is a legitimate open-source endpoint monitoring, digital forensics, and incident response platform that threat actors repurpose as a backdoor and command-and-control framework. Its presence alone does not indicate malicious activity. Unauthorized deployments allow attackers to remotely execute commands, maintain access, and stage additional tooling on compromised endpoints.
Observed abuse involves Windows agents deployed through silent MSI installations and configured to communicate with attacker-controlled infrastructure, including Cloudflare Workers. Attackers have used Velociraptor to launch encoded PowerShell commands, download and execute Visual Studio Code to establish remote-access tunnels, and load additional .NET payloads directly into memory. Some deployments run as Windows services, supporting persistent access. The use of legitimate forensic software and trusted cloud infrastructure helps conceal malicious remote administration.
Warlock operators, tracked as GOLD SALEM and Storm-2603, have repeatedly used Velociraptor in ransomware-related intrusions. Deployments have followed exploitation of Microsoft SharePoint, SmarterMail, and SolarWinds Web Help Desk systems. Version 0.73.4 has appeared repeatedly in these operations, including as the primary command-and-control framework. The Gentlemen ransomware operation also uses a modified version. Velociraptor supports the post-compromise access and execution stages of these attacks; it is distinct from the ransomware payloads that subsequently encrypt victim data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Between September and November 2025, Huntress observed ... abuse of the Velociraptor DFIR tool four times.
Between September and November 2025, Huntress observed ... abuse of the Velociraptor DFIR tool four times.
Threat actors have started to use the Velociraptor digital forensics and incident response (DFIR) tool in attacks that deploy LockBit and Babuk ransomware.
Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.
Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.
Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.
"CVE-2026-24423... exploits a weakness in the ConnectToHub API method to achieve unauthenticated remote code execution (RCE)."
"CVE-2026-23760 is an authentication bypass flaw that could allow any user to reset the SmarterMail system administrator password by sending a specially crafted HTTP request."
Huntress reported active exploitation of SolarWinds Web Help Desk vulnerabilities (CVE-2025-26399 and CVE-2025-40551) by unidentified threat actors, deploying remote management tools and Velociraptor for command and control.
Huntress reported active exploitation of SolarWinds Web Help Desk vulnerabilities (CVE-2025-26399 and CVE-2025-40551) by unidentified threat actors, deploying remote management tools and Velociraptor for command and control.
"Shortly after reconnaissance, the attacker deployed Velociraptor, an open-source DFIR platform... its ability to execute commands, collect artifacts, and remotely control endpoints makes it an effective command-and-control (C2) framework when misused."
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group also has its own custom tooling, including the G-BOT command-and-control (C2) framework and a modified version of Velociraptor.
The threat actors continued to abuse Velociraptor version 0.73.4 as their primary C&C framework, with its installer disguised as v4.msi.
Upon gaining initial access, the threat actor is said to have deployed tools like Velociraptor to blend malicious activity with trusted administrative behavior...
...followed by dropping additional payloads like Velociraptor and the locker to encrypt files.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
After gaining initial access via exploitation of the flaw (CVE-2025-59287), the actors then installed Velociraptor... This deserialization issue has previously been exploited by threat actors targeting vulnerable WSUS instances exposed publicly on their default ports.
These tactics are in addition to previous post-exploit tools and techniques used by the group, which included the Velociraptor digital forensics and incident response (DFIR) tool as its primary command-and-control (C2) framework...
we observed a number of base64-encoded PowerShell commands, which were child processes of Velociraptor.exe
buildx641 ... uses vssadmin, shadow copies, ntds.dit, and SYSTEM copies... Velociraptor ... including memory and LSASS dumping... KslDump dumps Kerberos / LSASS-related material.
These commands launched a series of discovery queries, allowing the threat actor to gather information about users, running services, configurations, and more.
Velociraptor... was configured to communicate with the endpoint update[.]githubtestbak[.]workers[.]dev .
For remote access and C2, they rely on frameworks like ZeroPulse and Velociraptor, combined with Cloudflare-based tunnels and custom VPN setups to keep stable access into compromised networks.
G-BOT supports Linux and Windows beacons, live command execution, beacon management, and SOCKS proxying; Velociraptor and ZeroPulse were also used as C2 frameworks.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate DFIR tool explicitly weaponized for remote execution and command and control. Operators spawned encoded PowerShell and established Visual Studio Code and Cloudflare tunnels; three observed deployments used workers.dev C2 endpoints.
Legitimate DFIR software repurposed as the primary C2 framework. It downloaded VS Code and launched fileless PowerShell payloads using reflective .NET assembly loading.
A modified version of Velociraptor is identified as custom tooling used by The Gentlemen in its attack operations. This entry concerns the actor-modified version, not the legitimate software generally; the content does not specify its modifications or capabilities.
Used here as a covert C2 and for LSASS/memory collection, but it is primarily a legitimate DFIR tool rather than malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.