A new malicious campaign is exposing serious weaknesses in SolarWinds Web Help Desk (WHD), with attackers exploiting critical vulnerabilities to install legitimate tools, turning them into weapons for malicious purposes.

Attackers appear to be targeting high-value organizations, using persistence techniques and remote access tools , such as Zoho ManageEngine Assist , as well as Cloudflare infrastructure to maintain control of systems.
Activity detection by Huntress Security
The malicious activity was uncovered over the weekend by researchers at Huntress Security, who believe it was a campaign that began as early as January 16.
See also: PayPal and Apple Abuse for DKIM Replay Attacks
According to Huntress, on February 7, 2026, SOC analyst Dipo Rodipe investigated a SolarWinds WHD exploit incident, where the perpetrators directly deployed Zoho tunnels and Cloudflare tunnels for persistence, while also using the Velociraptor as a command and control (C2) infrastructure.
SolarWinds: Vulnerabilities being exploited
The attackers exploited two critical security vulnerabilities:
- CVE-2025-40551, which CISA recently identified as being actively used in attacks
- CVE-2025-26399
Both vulnerabilities have been rated “critical,” allowing remote unauthenticated. This means an attacker could gain access to a WHD server without even having credentials.
Microsoft researchers have also observed intrusions into exposed WHD installations, but have not directly confirmed the exploitation of these CVEs .

Attack Chain: From Initial Access to Full Penetration
After the initial breach, the perpetrators install the Zoho ManageEngine Assist via an MSI file hosted on the Catbox platform.
See also: Phishing attack targets Apple Pay users
The tool is configured for unattended access, while the compromised system is logged into a Zoho account linked to an anonymous Proton Mail.
Through this, attackers carry out:
- hands-on keyboard activity
- Active Directory (AD) recognition
- preparation for next stages of attack
Velociraptor: From DFIR tool to C2 platform
One of the most concerning elements is the misuse of Velociraptor, a legitimate digital forensics and incident response tool.
Cisco Talos has already warned that Velociraptor is increasingly being used in ransomware attacks.
In this case, the platform is being exploited as a C2, communicating via Cloudflare Workers. In addition, the perpetrators used the old version 0.73.4, which contains a privilege escalation vulnerability, allowing elevation of privileges on the host.

Cloudflare tunnels and persistence techniques
The attackers also installed Cloudflared from Cloudflare's official GitHub repository, creating an alternative tunnel-based access channel for redundancy.
In some environments, persistence was maintained via a scheduled task (TPMProfiler), which opened an SSH backdoor via QEMU.
See also: Bloody Wolf targets Uzbekistan and Russia with NetSupport RAT
Disabling defenses and additional payloads
To ensure that additional payloads, the perpetrators disabled:
- Windows Defender
- Windows Firewall
via registry modifications.
In fact, according to the researchers, almost immediately after disabling Defender, they downloaded a new copy of the VS Code binary, presumably for use as a script execution and further management tool.

Protection measures and mitigation
System administrators are urged to take immediate action:
- Upgrade SolarWinds WHD to version 2026.1 or later
- Removing public access to admin interfaces
- Reset all product-related credentials
Huntress also published Sigma rules and indicators of compromise for detecting Zoho Assist, Velociraptor, Cloudflared, VS Code activity, and suspicious MSI installations.
Despite the scope of the campaign, neither Microsoft nor Huntress attributed the attack to a specific group, with the targets simply described as "high-value assets.".
Source: www.bleepingcomputer.com
