Velociraptor is a legitimate open-source digital forensics and incident response (DFIR) platform that threat actors have repeatedly abused as a covert command-and-control, remote access, persistence, and staging tool in ransomware intrusions. The content describes its misuse across multiple campaigns rather than as a standalone malware family. Reported capabilities when abused include executing commands, collecting artifacts, remotely controlling endpoints, establishing C2 communications, and enabling or supporting Visual Studio Code tunnel- and Cloudflare tunnel-based access. Threat actors were observed deploying Velociraptor via MSI installers such as v2.msi, v3.msi, and v4.msi, including payloads hosted on Cloudflare Workers infrastructure and Supabase. Observed C2-related infrastructure included velo[.]qaubctgg[.]workers[.]dev, auth.qgtxtebl.workers[.]dev, royal-boat-bf05.qgtxtebl.workers[.]dev, and chat.hcqhajfv.workers[.]dev. Multiple reports specifically note abuse of Velociraptor version 0.73.4/0.73.4.0, described as outdated and susceptible to CVE-2025-6264, enabling arbitrary command execution, privilege escalation, or endpoint takeover. The tool was observed in intrusions associated with Warlock ransomware and the threat group GOLD SALEM / Storm-2603, including exploitation of SharePoint ToolShell, SmarterMail, SolarWinds Web Help Desk, and Gladinet Triofox-related intrusion chains. It was also cited as part of The Gentlemen / Storm-2697 ransomware ecosystem and in broader ransomware activity involving LockBit and Babuk. In observed incidents, attackers used Velociraptor to blend malicious activity with trusted administrative behavior, maintain persistence, establish backdoor access, set the stage for ransomware deployment, and in some cases drop additional payloads before file encryption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Huntress analysts detected an incident where threat actors likely exploited a recently patched remote code execution vulnerability in Windows Server Update Services (WSUS). After gaining initial access via exploitation of the flaw (CVE-2025-59287), the actors then installed Velociraptor... This deserialization issue has previously been exploited by threat actors targeting vulnerable WSUS instances exposed publicly on their default ports; as of October 23, a patch is available from Microsoft.
Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.
Threat actors have started to use the Velociraptor digital forensics and incident response (DFIR) tool in attacks that deploy LockBit and Babuk ransomware.
Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.
Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.
Velociraptor is a digital forensics and incident response (DFIR) tool that we have seen threat actors abuse recently in attacks in order to set up command-and-control (C2) communications.
"CVE-2026-24423... exploits a weakness in the ConnectToHub API method to achieve unauthenticated remote code execution (RCE)."
"CVE-2026-23760 is an authentication bypass flaw that could allow any user to reset the SmarterMail system administrator password by sending a specially crafted HTTP request."
Huntress reported active exploitation of SolarWinds Web Help Desk vulnerabilities (CVE-2025-26399 and CVE-2025-40551) by unidentified threat actors, deploying remote management tools and Velociraptor for command and control.
Huntress reported active exploitation of SolarWinds Web Help Desk vulnerabilities (CVE-2025-26399 and CVE-2025-40551) by unidentified threat actors, deploying remote management tools and Velociraptor for command and control.
"Shortly after reconnaissance, the attacker deployed Velociraptor, an open-source DFIR platform... its ability to execute commands, collect artifacts, and remotely control endpoints makes it an effective command-and-control (C2) framework when misused."
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Upon gaining initial access, the threat actor is said to have deployed tools like Velociraptor to blend malicious activity with trusted administrative behavior...
...followed by dropping additional payloads like Velociraptor and the locker to encrypt files.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
After gaining initial access via exploitation of the flaw (CVE-2025-59287), the actors then installed Velociraptor... This deserialization issue has previously been exploited by threat actors targeting vulnerable WSUS instances exposed publicly on their default ports.
These tactics are in addition to previous post-exploit tools and techniques used by the group, which included the Velociraptor digital forensics and incident response (DFIR) tool as its primary command-and-control (C2) framework...
After the threat actor installed Velociraptor, we observed a number of base64-encoded PowerShell commands, which were child processes of Velociraptor.exe...
we observed a number of base64-encoded PowerShell commands, which were child processes of Velociraptor.exe
Since Velociraptor is widely trusted and commonly used by security teams, its presence blended seamlessly with normal administrative behavior, making it an effective cover for malicious activity running in plain sight.
Velociraptor Used as a covert C2 platform, including memory and LSASS dumping... KslDump Dumps Kerberos / LSASS-related material... buildx641 ... uses ... ntds.dit, and SYSTEM copies...
These commands launched a series of discovery queries, allowing the threat actor to gather information about users, running services, configurations, and more.
The group deployed Velociraptor, a legitimate forensic tool, running it with the highest system privileges to map the environment and collect data.
Velociraptor... was configured to communicate with the endpoint update[.]githubtestbak[.]workers[.]dev .
For remote access and C2, they rely on frameworks like ZeroPulse and Velociraptor, combined with Cloudflare-based tunnels and custom VPN setups to keep stable access into compromised networks.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used here as a covert C2 and for LSASS/memory collection, but it is primarily a legitimate DFIR tool rather than malware.
A covert remote access/C2 platform used by the operators, including for memory and LSASS dumping, as part of ransomware intrusion workflows.
A legitimate DFIR platform repurposed by the threat actors as their primary command-and-control framework for stealthy persistence and remote operations.
Legitimate DFIR/endpoint visibility tool repurposed by threat actors for command-and-control, persistence, and reconnaissance in intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.