Threat actors likely exploited the Windows Server Update Services (WSUS) remote code execution vulnerability CVE-2025-59287 to gain initial access, then installed the legitimate open-source forensic tool Velociraptor for command and control, Huntress reported. The attackers retrieved a malicious MSI package from s3[.]wasabisys[.]com and configured the client to communicate with update[.]githubtestbak[.]workers[.]dev. They subsequently ran Base64-encoded PowerShell commands and utilities to enumerate users, network configuration, and services. Huntress contained the incident and reported increased Velociraptor abuse during 2025, following its first observations in November 2024.
The incident illustrates a broader shift toward command-and-control channels that exploit trusted tools and permitted cloud traffic. Inde Technology highlighted Discord-based exfiltration, UAT-11587’s use of Microsoft Graph, SesameOp’s abuse of the OpenAI Assistants API, and ransomware operators’ use of legitimate administration tools. It also described experimental blockchain-based and Cloudflare Queues-based C2 implementations. These approaches complicate detection and takedowns, while blanket blocking can disrupt business services. Defensive priorities include patching and hardening WSUS and other privileged infrastructure, investigating unexpected administration-tool deployments, strengthening identity and endpoint controls, segmenting networks, and maintaining resilient backups rather than relying primarily on short-lived network indicators.

See which actors are running it and whether you're in range.
19 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos reported the UAT-11587 campaign and assessed the actor with high confidence as China-nexus. Its Rust backdoor used an attacker-registered Entra ID application to access Microsoft Graph, upload OneDrive heartbeats, and poll Outlook for commands; Cloudflare Pages and R2 staged its infection chain.
Microsoft reported an ACR Stealer ClickFix campaign that retrieved a payload or command-and-control address from a blockchain smart contract.
Huntress observed attackers deploy Velociraptor after gaining initial access through likely exploitation of WSUS vulnerability CVE-2025-59287. They retrieved an MSI from s3[.]wasabisys[.]com, installed an auto-start LocalSystem service, and configured it to communicate with update[.]githubtestbak[.]workers[.]dev.
Microsoft disclosed SesameOp following an incident-response investigation that found operators using hijacked Visual Studio utilities over several months. The malware used the OpenAI Assistants API as a command-and-control relay without invoking AI models.
Microsoft had made a patch available by October 23 for CVE-2025-59287, a deserialization vulnerability enabling remote code execution in Windows Server Update Services.
Cisco Talos publicly documented Velociraptor activity and attributed it with medium confidence to Storm-2603. Talos assessed that initial access in that case likely involved SharePoint ToolShell vulnerabilities.
According to Cisco Talos's subsequent reporting, UAT-11587 deployed a Rust backdoor against government and policy targets beginning in September 2025. The campaign ultimately affected approximately 350 endpoints across 16 environments in eight Asian countries.
Huntress SOC first observed threat actors misusing Velociraptor, a legitimate open-source digital forensics and incident response tool.
An intrusion investigated by IBM X-Force involved a Raspberry Pi Zero running P4wnP1 plugged into a self-checkout terminal. A JavaScript Discord bot encrypted and exfiltrated .dat files, while a gaming-traffic alert on the point-of-sale network indicated compromise.
An eight-country law enforcement operation took down Emotet, which had compromised more than one million hosts and operated several hundred servers across three botnets.
The article's author open-sourced a Mythic command-and-control profile that uses Cloudflare Queues as an asynchronous dead drop behind an authenticated public Worker endpoint. The profile supports the author's Thanatos agent fork and keeps Cloudflare account credentials out of the implant.
The article's author developed graphcat, an experimental framework that uses a public blockchain as an encrypted command-and-control message queue and HTTPS polling for agent communications. The author stated that there was no current intention to release it publicly.
Qilin operators used Splashtop's management service to execute Linux ransomware on Windows hosts through Windows Subsystem for Linux.
Trend Micro observed a Qilin affiliate using Atera to deploy AnyDesk, with ScreenConnect providing an additional remote-access channel.
Huntress SOC analysts contained the threat actor's activity in the WSUS incident.
Following installation in the WSUS incident, Velociraptor spawned multiple base64-encoded PowerShell commands using unrestricted execution policy. The attackers ran net.exe, quser.exe, setspn.exe, and ipconfig.exe to gather information about domain computers, users, services, and network configuration.
After successfully installing Velociraptor, the attackers made two additional attempts to run the same installation command from the same location.
Across September–November 2025, Huntress observed four Velociraptor-abuse cases, including the WSUS incident, two cases involving SharePoint ToolShell web shells, and one involving a Warlock ransom note. Operators used encoded PowerShell and Visual Studio Code and Cloudflare tunnels; three cases used workers.dev domains for Velociraptor command and control.
Emotet reemerged after the January 2021 eight-country takedown operation. The reference does not specify when its return occurred.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.