Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Threat Actors Abuse Velociraptor Incident Response Tool to Gain Remote Access

Threat Actors Abuse Velociraptor Incident Response Tool to Gain Remote Access

Posted on August 28, 2025August 28, 2025 By CWS

A complicated intrusion during which menace actors co-opted the reliable, open-source Velociraptor digital forensics and incident response (DFIR) software to determine a covert distant entry channel.

This represents an evolution from the long-standing tactic of abusing distant monitoring and administration (RMM) utilities, with attackers now repurposing DFIR frameworks to reduce customized malware deployment and evade detection.

Through the assault, the adversary leveraged the native Home windows msiexec utility to obtain and set up a malicious Velociraptor MSI bundle from a Cloudflare Employees–hosted staging area, recordsdata.qaubctgg.employees.dev.

This staging space additionally housed different attacker instruments, comparable to a Cloudflare tunneling element and the Radmin distant administration software. As soon as put in, Velociraptor was configured to speak with a command-and-control (C2) server at velo.qaubctgg.employees[.]dev.

Subsequent, the intruder executed an obfuscated PowerShell command to retrieve Visible Studio Code (code.exe) from the identical employees.dev folder and ran it with the built-in tunnel characteristic enabled.

Course of tree exhibiting Velociraptor creating Visible Studio Code tunnel.

By putting in code.exe as a Home windows service and redirecting its output to a log file, the menace actor successfully created a persistent, encrypted tunnel to the attacker’s C2 infrastructure.

This system bypassed many conventional safety controls, because the tunneling characteristic in Visible Studio Code is usually used legitimately by builders for distant collaboration, in keeping with Sophos’ investigation.

In response, CTU analysts offered the affected group with mitigation steering, enabling speedy isolation of the compromised host. This containment measure prevented the adversary from advancing to their final objective of ransomware deployment.

Though distant entry abuse by way of RMM instruments is a well-recognized tactic documented in earlier incidents involving SimpleHelp vulnerabilities and digital machine–primarily based instruments, this case marks one of many first noticed cases during which DFIR software program itself was weaponized.

By pivoting to Velociraptor, the attackers decreased reliance on bespoke malware, reducing their operational footprint and complicating attribution.

CTU’s evaluation signifies that this tradecraft must be handled as a probable precursor to ransomware. Organizations are subsequently suggested to:

Monitor unauthorized deployments of DFIR and incident response instruments, together with Velociraptor, throughout endpoints and servers.

Implement complete EDR methods able to detecting atypical processes and suspicious command traces.

Implement strict utility allow-listing insurance policies to dam unapproved installers and repair creations.

Frequently audit community site visitors for surprising encrypted tunnels or anomalous C2 beaconing.

Keep sturdy, offline backups and rehearse ransomware restoration plans.

Safety groups ought to assessment and prohibit entry to those domains, considering the danger of interacting with probably malicious content material.

Indicator TypeDomainDescriptionInstallerfiles.qaubctgg.employees.dev/v2.msiVelociraptor MSI packageTunneling Toolfiles.qaubctgg.employees.dev/code.exeVisual Studio Code executableAdditional MSIworkers.dev/sc.msiSecondary malware installer

By treating unauthorized use of incident response instruments as a high-risk occasion and adopting layered detection and prevention measures, organizations can considerably scale back the influence of such assaults and halt adversaries earlier than they deploy ransomware.

Discover this Story Fascinating! Comply with us on LinkedIn and X to Get Extra On the spot Updates.

Cyber Security News Tags:Abuse, Access, Actors, Gain, Incident, Remote, Response, Threat, Tool, Velociraptor

Post navigation

Previous Post: Nevada IT Systems Hit by Cyberattack
Next Post: MathWorks Confirms Cyberattack, User Personal Information Stolen

Related Posts

Threat Actors Attacking Azure Blob Storage to Compromise Organizational Repositories Threat Actors Attacking Azure Blob Storage to Compromise Organizational Repositories Cyber Security News
New GhostPairing Attack Let Attackers Gain Full Access in WhatsApp with Phone Number New GhostPairing Attack Let Attackers Gain Full Access in WhatsApp with Phone Number Cyber Security News
MuddyWater Embraces Russian Malware in ChainShell Attack MuddyWater Embraces Russian Malware in ChainShell Attack Cyber Security News
251 Malicious IPs Attacking Cloud-Based Devices Leveraging 75 Exposure Points 251 Malicious IPs Attacking Cloud-Based Devices Leveraging 75 Exposure Points Cyber Security News
PhantomVAI Loader Attacking Organizations Worldwide to Deliver AsyncRAT, XWorm, FormBook and DCRat PhantomVAI Loader Attacking Organizations Worldwide to Deliver AsyncRAT, XWorm, FormBook and DCRat Cyber Security News
Hackers Exploiting Three-Year-Old FortiGate Vulnerability to Bypass 2FA on Firewalls Hackers Exploiting Three-Year-Old FortiGate Vulnerability to Bypass 2FA on Firewalls Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cybercriminals Exploit AI to Steal Android App Secrets
  • Chinese Hackers Exploit Sogou Input Flaw for Attack
  • Casbaneiro Trojan Targets Latin American Banks
  • CISOs Tackle AI Risks While Balancing Innovation
  • GitHub Awards Record $100K for Major RCE Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cybercriminals Exploit AI to Steal Android App Secrets
  • Chinese Hackers Exploit Sogou Input Flaw for Attack
  • Casbaneiro Trojan Targets Latin American Banks
  • CISOs Tackle AI Risks While Balancing Innovation
  • GitHub Awards Record $100K for Major RCE Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark