Active in-the-wild exploitation of SolarWinds Web Help Desk (WHD) vulnerabilities is being used to achieve remote code execution (RCE) on unpatched servers, followed by rapid deployment of legitimate remote administration tooling for persistence and interactive control. Huntress reported intrusions originating from the WHD service (via wrapper.exe spawning java.exe in the Tomcat-based application), where attackers executed cmd.exe to install a Zoho ManageEngine/Zoho Assist RMM agent for unattended access; at least one observed Zoho Assist registration was tied to a Proton Mail address (esmahyft@proton[.]me). The activity is linked to recently disclosed WHD issues, including CVE-2025-40551 (untrusted deserialization leading to code execution, added to CISA KEV) and CVE-2025-26399, which multiple vendors have cited as being exploited in the wild.
Post-compromise, the actor used the Zoho RMM process (TOOLSIQ.EXE) as an operational foothold to run Active Directory discovery and domain enumeration (e.g., net group "domain computers" /do) consistent with preparation for lateral movement. The intrusions also included deployment of Velociraptor for endpoint control and collection, and use of Cloudflare tunnels to maintain access and route traffic. Huntress noted broad exposure in its ecosystem (84 endpoints across 78 organizations running WHD), indicating a sizable attack surface for organizations that have not patched or mitigated affected WHD instances.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Belgium's Center for Cybersecurity issued an advisory warning that SolarWinds Web Help Desk vulnerabilities were being actively exploited and urged immediate patching. The notice reflected the spread of official government warnings beyond vendor and U.S. agency reporting.
By February 9, multiple security outlets and researchers had published consolidated reporting that the campaign was actively exploiting unpatched SolarWinds WHD servers for unauthenticated RCE and follow-on abuse of legitimate admin and DFIR tools. Reporting also tied the activity to public staging services, Cloudflare Worker-fronted infrastructure, and in some cases QEMU-based SSH backdoor persistence.
On February 7, Huntress observed attackers exploit an unpatched WHD instance, then silently install Zoho Assist from Catbox, perform Active Directory reconnaissance, and deploy Velociraptor from a Supabase bucket. The actor also disabled Windows Defender and the firewall, used Cloudflared for tunnel access, and exfiltrated system information to an attacker-controlled Elastic Cloud instance.
CISA added CVE-2025-40551 to the Known Exploited Vulnerabilities catalog after evidence of in-the-wild exploitation. The agency ordered U.S. FCEB agencies to remediate by February 6, 2026.
On February 6, Microsoft publicly stated that SolarWinds Web Help Desk servers were under active exploitation. It described post-compromise use of PowerShell, BITS, Zoho ManageEngine tooling, reverse SSH/RDP access, credential dumping, and persistence mechanisms including scheduled tasks launching QEMU.
Microsoft Defender Research reported that it had detected multi-stage intrusions affecting customers in December 2025 through vulnerable SolarWinds WHD servers. The attacks involved lateral movement, credential theft, and in at least one case DCSync, but Microsoft could not determine which WHD CVE was used for initial access.
SolarWinds disclosed additional Web Help Desk vulnerabilities, including CVE-2025-40551 and CVE-2025-40536. These newly disclosed issues were later considered possible initial access vectors in the active intrusions.
Threat activity against internet-exposed SolarWinds Web Help Desk instances began by at least mid-January 2026, with Huntress later saying the campaign started around January 16. At least three organizations were affected in the observed activity.
A critical deserialization remote code execution flaw, CVE-2025-26399, in SolarWinds Web Help Desk was publicly disclosed. Later reporting identified it as one of the vulnerabilities present on systems that were subsequently attacked.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
ccb.belgium.be
Open sourcescworld.com
Open sourcehelpnetsecurity.com
Open sourcecsoonline.com
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.