Hackers Exploit SolarWinds WHD Vulnerabilities to Deploy Malicious Tools
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Hackers have been exploiting vulnerabilities in SolarWinds Web Help Desk (WHD), specifically CVE-2025-40551 and CVE-2025-26399, to deploy legitimate tools for malicious purposes. This activity was identified by Huntress Security, which noted that the attacks began on January 16, 2026. The threat actor targeted at least three organizations, using tools like Zoho ManageEngine and Velociraptor to establish command and control (C2) capabilities.
After gaining access, the attackers installed the Zoho ManageEngine Assist agent and configured it for unattended access, linking it to an anonymous Proton Mail account. They also deployed Velociraptor, a digital forensics and incident response tool, which has been previously warned about by Cisco Talos for its misuse in ransomware attacks. The attackers used an outdated version of Velociraptor, which is vulnerable to privilege escalation, further complicating the security landscape.
The attackers utilized Cloudflare tunnels for persistent access and disabled Windows Defender and Firewall to facilitate their operations. They also created a scheduled task to maintain access through an SSH backdoor. These actions highlight the sophisticated nature of the attack chain, which involved multiple stages and tools.
Implications for Cybersecurity
This incident underscores the importance of timely updates and security measures for organizations using SolarWinds WHD. The vulnerabilities exploited are rated as critical, allowing remote code execution without authentication. Organizations should be vigilant about their configurations and access controls to mitigate similar risks.
System administrators are advised to upgrade SolarWinds WHD to version 2026.1 or later and to remove public internet access to admin interfaces. Resetting all associated credentials is also crucial to prevent unauthorized access.
Huntress has provided Sigma rules and indicators of compromise to assist in detecting related malicious activities, including silent MSI installations and encoded PowerShell executions. Organizations should implement these detection mechanisms to enhance their security posture against such attacks.
Key Takeaways
- Upgrade SolarWinds Web Help Desk to version 2026.1 or later to patch vulnerabilities.
- Remove public internet access to SolarWinds WHD admin interfaces to reduce exposure.
- Reset all credentials associated with SolarWinds WHD to prevent unauthorized access.
- Implement detection mechanisms for tools like Zoho Assist and Velociraptor to identify potential compromises.
- Regularly review and update security configurations to protect against similar attack vectors.
Key Terms & Concepts
- CVE-2025-40551: In this article, CVE-2025-40551 refers to a critical vulnerability in SolarWinds Web Help Desk that allows remote code execution without authentication.
- Velociraptor: In this article, Velociraptor is a legitimate digital forensics and incident response tool that has been misused in cyberattacks.
- Zoho ManageEngine: In this article, Zoho ManageEngine is a remote monitoring and management tool that attackers exploited for malicious purposes.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.