HomeSecurityHackers exploit SolarWinds WHD vulnerabilities

Hackers exploit SolarWinds WHD vulnerabilities

A new malicious campaign is exposing serious weaknesses in SolarWinds Web Help Desk (WHD), with attackers exploiting critical vulnerabilities to install legitimate tools, turning them into weapons for malicious purposes.

SolarWinds WHD vulnerabilities

Attackers appear to be targeting high-value organizations, using persistence techniques and remote access tools , such as Zoho ManageEngine Assist , as well as Cloudflare infrastructure to maintain control of systems.

Activity detection by Huntress Security

The malicious activity was uncovered over the weekend by researchers at Huntress Security, who believe it was a campaign that began as early as January 16.

See also: PayPal and Apple Abuse for DKIM Replay Attacks

According to Huntress, on February 7, 2026, SOC analyst Dipo Rodipe investigated a SolarWinds WHD exploit incident, where the perpetrators directly deployed Zoho tunnels and Cloudflare tunnels for persistence, while also using the Velociraptor as a command and control (C2) infrastructure.

SolarWinds: Vulnerabilities being exploited

The attackers exploited two critical security vulnerabilities:

  • CVE-2025-40551, which CISA recently identified as being actively used in attacks
  • CVE-2025-26399

Both vulnerabilities have been rated “critical,” allowing remote unauthenticated. This means an attacker could gain access to a WHD server without even having credentials.

Microsoft researchers have also observed intrusions into exposed WHD installations, but have not directly confirmed the exploitation of these CVEs .

Hackers exploit SolarWinds WHD vulnerabilities

Attack Chain: From Initial Access to Full Penetration

After the initial breach, the perpetrators install the Zoho ManageEngine Assist via an MSI file hosted on the Catbox platform.

See also: Phishing attack targets Apple Pay users

The tool is configured for unattended access, while the compromised system is logged into a Zoho account linked to an anonymous Proton Mail.

Through this, attackers carry out:

  • hands-on keyboard activity
  • Active Directory (AD) recognition
  • preparation for next stages of attack

Velociraptor: From DFIR tool to C2 platform

One of the most concerning elements is the misuse of Velociraptor, a legitimate digital forensics and incident response tool.

Cisco Talos has already warned that Velociraptor is increasingly being used in ransomware attacks.

In this case, the platform is being exploited as a C2, communicating via Cloudflare Workers. In addition, the perpetrators used the old version 0.73.4, which contains a privilege escalation vulnerability, allowing elevation of privileges on the host.

Hackers exploit SolarWinds WHD vulnerabilities

Cloudflare tunnels and persistence techniques

The attackers also installed Cloudflared from Cloudflare's official GitHub repository, creating an alternative tunnel-based access channel for redundancy.

In some environments, persistence was maintained via a scheduled task (TPMProfiler), which opened an SSH backdoor via QEMU.

See also: Bloody Wolf targets Uzbekistan and Russia with NetSupport RAT

Disabling defenses and additional payloads

To ensure that additional payloads, the perpetrators disabled:

  • Windows Defender
  • Windows Firewall

via registry modifications.

In fact, according to the researchers, almost immediately after disabling Defender, they downloaded a new copy of the VS Code binary, presumably for use as a script execution and further management tool.

Hackers exploit SolarWinds WHD vulnerabilities

Protection measures and mitigation

System administrators are urged to take immediate action:

  • Upgrade SolarWinds WHD to version 2026.1 or later
  • Removing public access to admin interfaces
  • Reset all product-related credentials

Huntress also published Sigma rules and indicators of compromise for detecting Zoho Assist, Velociraptor, Cloudflared, VS Code activity, and suspicious MSI installations.

Despite the scope of the campaign, neither Microsoft nor Huntress attributed the attack to a specific group, with the targets simply described as "high-value assets.".

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS