Ransomware operators have begun leveraging Velociraptor, an open-source digital forensics and incident response (DFIR) tool, to facilitate and enhance their attacks on enterprise environments. Cisco Talos confirmed that Velociraptor, previously not definitively linked to ransomware campaigns, was used by threat actors believed to be associated with Storm-2603 and possibly a China-based group. These actors targeted VMware ESXi virtual machines and Windows servers, deploying multiple ransomware strains including Warlock, LockBit, and Babuk, which resulted in significant disruption to the victim's IT infrastructure. The attackers installed an outdated version of Velociraptor (0.73.4.0) that contained a privilege escalation vulnerability (CVE-2025-6264), enabling them to execute arbitrary commands and potentially take over endpoints. Velociraptor was used to maintain stealthy, persistent access, allowing the attackers to operate undetected while preparing and executing the ransomware payloads. In addition to Velociraptor, the attackers utilized the Windows msiexec utility to download and install tools from a Cloudflare Workers domain, including Visual Studio Code and the Radmin remote administration tool, further expanding their control and tunneling capabilities. Visual Studio Code was installed as a service and configured to create a tunnel to an attacker-controlled command-and-control (C2) server, with logs redirected for monitoring. The attackers also used encoded PowerShell commands to automate the download and execution of these tools. Sophos incident responders encountered the same threat actors in a separate incident, where they were able to prevent the final deployment of ransomware, but observed the same tactics, techniques, and procedures (TTPs). The use of Velociraptor in these attacks highlights a growing trend of threat actors repurposing legitimate security tools for malicious purposes, complicating detection and response efforts. The campaign demonstrates the attackers' ability to combine multiple open-source and commercial tools to achieve persistence, lateral movement, and data exfiltration. The presence of Babuk ransomware files on the victim's network marks a new development, as this strain had not previously been associated with Storm-2603. The attackers' use of multiple ransomware variants in a single campaign suggests a flexible and opportunistic approach to maximizing impact. The exploitation of a known vulnerability in Velociraptor underscores the importance of timely patching and monitoring of security tools themselves. The campaign also involved the use of Cloudflare tunneling and remote administration utilities, indicating a sophisticated approach to maintaining access and evading detection. The incident serves as a warning to organizations about the risks of outdated or misconfigured security tools being turned against them. Security teams are advised to monitor for unusual deployments of DFIR tools and to ensure all such software is kept up to date. The blending of legitimate and malicious activity in these attacks poses significant challenges for defenders, requiring enhanced vigilance and advanced detection capabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting cited Halcyon as assessing that Storm-2603 may have ties to Chinese nation-state actors. The assessment referenced ToolShell access patterns, OPSEC measures, China Standard Time build artifacts, and shared infrastructure across Warlock, LockBit, and Babuk activity.
Following public reporting, researchers advised organizations to update Velociraptor to version 0.73.5 or later to mitigate the privilege-escalation issue tracked as CVE-2025-6264. The guidance came as the campaign highlighted the risks of attackers weaponizing legitimate open-source DFIR tools.
On October 9, 2025, Cisco Talos published research attributing the August intrusion to Storm-2603 with moderate confidence based on overlapping tools, tradecraft, and the unusual use of multiple ransomware families. The report publicly detailed the abuse of Velociraptor for stealthy persistence in ransomware attacks.
The intrusion culminated in deployment of multiple ransomware families in a single engagement: LockBit and Warlock-associated encryption on Windows systems and Babuk on VMware ESXi virtual machines. The attack caused severe operational impact and marked the first public association of Storm-2603 with Babuk ransomware.
The attackers used PowerShell-based scripts to exfiltrate data to an external IP address before or alongside encryption, indicating a double-extortion component. Reporting also describes a separate fileless PowerShell encryptor used in the operation.
During the intrusion, the actors used the vulnerable Velociraptor build associated with CVE-2025-6264, though Talos could not confirm direct exploitation of the flaw. They also created administrative accounts, modified Group Policy, disabled or weakened Microsoft Defender protections, and used Impacket Smbexec for lateral movement.
In August 2025, Cisco Talos observed a ransomware intrusion in which attackers installed an outdated Velociraptor version 0.73.4.0 to maintain persistence and control compromised systems. The activity targeted Windows servers and VMware ESXi infrastructure and included access to VMware vSphere.
Reporting indicates the threat actor used on-premises Microsoft SharePoint "ToolShell" vulnerabilities to obtain initial access before deploying follow-on tooling in the victim environment. This initial compromise is described as preceding the August 2025 ransomware intrusion.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcesecurityonline.info
Open sourcecsoonline.com
Open sourceblog.talosintelligence.com
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.