Velociraptor is a legitimate open-source endpoint visibility, digital forensics, and incident-response (DFIR) platform. It supports remote endpoint management, command execution, collection of forensic artifacts, and centralized client-server communications. Threat actors have repeatedly repurposed it as a covert command-and-control framework and remote-access backdoor following exploitation of internet-facing services. Observed abuse includes deployment as a Windows service, remote command execution, delivery and in-memory execution of additional payloads, and use alongside tunneling services such as Visual Studio Code and Cloudflare Tunnel to retain access and blend into legitimate administrative or development traffic. It has been used in intrusions associated with Storm-2603/GOLD SALEM and Warlock ransomware, including activity following exploitation of Microsoft SharePoint, SolarWinds Web Help Desk, SmarterMail, and WSUS vulnerabilities. The software is not inherently malware; its risk arises from unauthorized deployment and malicious configuration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Huntress analysts detected an incident where threat actors likely exploited a recently patched remote code execution vulnerability in Windows Server Update Services (WSUS). After gaining initial access via exploitation of the flaw (CVE-2025-59287), the actors then installed Velociraptor... This deserialization issue has previously been exploited by threat actors targeting vulnerable WSUS instances exposed publicly on their default ports; as of October 23, a patch is available from Microsoft.
Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.
Threat actors have started to use the Velociraptor digital forensics and incident response (DFIR) tool in attacks that deploy LockBit and Babuk ransomware.
Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.
Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.
Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.
"CVE-2026-24423... exploits a weakness in the ConnectToHub API method to achieve unauthenticated remote code execution (RCE)."
"CVE-2026-23760 is an authentication bypass flaw that could allow any user to reset the SmarterMail system administrator password by sending a specially crafted HTTP request."
Huntress reported active exploitation of SolarWinds Web Help Desk vulnerabilities (CVE-2025-26399 and CVE-2025-40551) by unidentified threat actors, deploying remote management tools and Velociraptor for command and control.
Huntress reported active exploitation of SolarWinds Web Help Desk vulnerabilities (CVE-2025-26399 and CVE-2025-40551) by unidentified threat actors, deploying remote management tools and Velociraptor for command and control.
"Shortly after reconnaissance, the attacker deployed Velociraptor, an open-source DFIR platform... its ability to execute commands, collect artifacts, and remotely control endpoints makes it an effective command-and-control (C2) framework when misused."
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The threat actors continued to abuse Velociraptor version 0.73.4 as their primary C&C framework, with its installer disguised as v4.msi.
Upon gaining initial access, the threat actor is said to have deployed tools like Velociraptor to blend malicious activity with trusted administrative behavior...
...followed by dropping additional payloads like Velociraptor and the locker to encrypt files.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
After gaining initial access via exploitation of the flaw (CVE-2025-59287), the actors then installed Velociraptor... This deserialization issue has previously been exploited by threat actors targeting vulnerable WSUS instances exposed publicly on their default ports.
These tactics are in addition to previous post-exploit tools and techniques used by the group, which included the Velociraptor digital forensics and incident response (DFIR) tool as its primary command-and-control (C2) framework...
we observed a number of base64-encoded PowerShell commands, which were child processes of Velociraptor.exe
Since Velociraptor is widely trusted and commonly used by security teams, its presence blended seamlessly with normal administrative behavior, making it an effective cover for malicious activity running in plain sight.
buildx641 ... uses vssadmin, shadow copies, ntds.dit, and SYSTEM copies... Velociraptor ... including memory and LSASS dumping... KslDump dumps Kerberos / LSASS-related material.
These commands launched a series of discovery queries, allowing the threat actor to gather information about users, running services, configurations, and more.
Velociraptor... was configured to communicate with the endpoint update[.]githubtestbak[.]workers[.]dev .
For remote access and C2, they rely on frameworks like ZeroPulse and Velociraptor, combined with Cloudflare-based tunnels and custom VPN setups to keep stable access into compromised networks.
The adversaries used [Velociraptor] for code execution and file staging ... such as disabling Microsoft Defender ... Other observations ... included ... disabling security controls such as Windows Defender and Window Firewall through registry key modifications.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate DFIR software repurposed as the primary C2 framework. It downloaded VS Code and launched fileless PowerShell payloads using reflective .NET assembly loading.
Used here as a covert C2 and for LSASS/memory collection, but it is primarily a legitimate DFIR tool rather than malware.
A legitimate DFIR platform repurposed by the threat actors as their primary command-and-control framework for stealthy persistence and remote operations.
Legitimate DFIR/endpoint visibility tool repurposed by threat actors for command-and-control, persistence, and reconnaissance in intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.