Hackers Exploit DFIR Tool ‘Velociraptor’ in Ransomware Attacks
Cisco Talos security researchers have identified that ransomware operators are exploiting Velociraptor, an open-source digital forensics and incident response (DFIR) tool, for malicious activities.
Cisco Talos security researchers have identified that ransomware operators are exploiting Velociraptor, an open-source digital forensics and incident response (DFIR) tool, for malicious activities.
This incident marks the first confirmed link between a legitimate security tool and a ransomware attack. The operation involved three distinct ransomware strains and is attributed, with moderate confidence, to the threat actor known as Storm-2603.
Velociraptor, intended for endpoint monitoring and data collection, was utilized by attackers to maintain stealthy and persistent access. The threat actors gained an initial foothold by installing an outdated version of Velociraptor (0.73.4.0), which has a known vulnerability (CVE-2025-6264) that allows for privilege escalation and arbitrary command execution. This enabled the deployment of LockBit and Babuk ransomware while evading detection.
This exploitation aligns with a broader trend where attackers leverage commercial and open-source tools to achieve their objectives. Cisco Talos attributes this activity to Storm-2603, a group believed to be based in China and first identified in July 2025, exploiting SharePoint vulnerabilities known as ToolShell.
The group is known for deploying Warlock and LockBit ransomware in the same attack. While LockBit is common, Warlock's use is a significant indicator, having been heavily used by this group since June 2025. The deployment of Warlock, LockBit, and Babuk in a single engagement is unusual and strengthens the link to Storm-2603.
First detected in mid-August 2025, the attack comprised a sophisticated series of events. Initial access was likely gained through the ToolShell exploit, followed by privilege escalation via new admin accounts synced to Entra ID. These accounts facilitated access to the VMware vSphere console, ensuring control over the virtual environment.
Defenses were impaired by modifying Active Directory Group Policy Objects (GPOs) to disable Microsoft Defender's real-time protection. A fileless PowerShell script executed the final encryption on Windows machines, while a Linux binary of the Babuk encryptor targeted ESXi servers.
This incident marks the first confirmed link between a legitimate security tool and a ransomware attack.
The attack also featured a double extortion component, involving the exfiltration of sensitive data using a custom PowerShell script, with techniques to evade detection such as suppressing progress indicators and employing sleep commands.
Indicator Type Indicator Value
C2/Exfiltration IP 65.38.121[.]226
Malicious MSI Domain stoaccinfoniqaveeambkp.blob.core.windows[.]net
Velociraptor C2 Server velo.qaubctgg.workers[.]dev
Velociraptor Installer SHA256 649BDAA38E60EDE6D140BD54CA5412F1091186A803D3905465219053393F6421
Velociraptor.exe SHA256 12F177290A299BAE8A363F47775FB99F305BBDD56BBDFDDB39595B43112F9FB7
Malicious config.yaml SHA256 A29125333AD72138D299CC9EF09718DDB417C3485F6B8FE05BA88A08BB0E5023
In.exe (NTLM Downgrade Tool) SHA256 C74897B1E986E2876873ABB3B5069BF1B103667F7F0E6B4581FBDA3FD647A74A
Based on reporting by Cyber Security News.
