Skip to main content

Threats Tagged 'velociraptor'

View all threats tagged with 'velociraptor'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: velociraptor

Threats Tagged 'velociraptor'

Click on any threat for detailed analysis and mitigation recommendations

The Warlock ransomware group has enhanced its attack chain with improved methods for persistence, lateral movement, and evasion. Their updated toolset includes TightVNC, Yuze, and a persistent BYOVD technique exploiting the NSec driver. The group's primary targets were technology, manufacturing, and government sectors, with the US, Germany, and Russia being the most affected countries. Warlock continues to exploit unpatched Microsoft SharePoint servers for initial access, and has expanded its post-exploitation toolkit. New additions include TightVNC for persistent remote access, Yuze for establishing SOCKS5 connections, and a BYOVD technique using the NSecKrnl.sys driver to terminate security products. The group also leverages Velociraptor, VS Code tunnels, and Cloudflare Tunnel for C&C communications.

Join the discussion

GOLD SALEM is a financially motivated cybercrime group deploying Warlock ransomware through sophisticated tradecraft, including exploiting SharePoint vulnerabilities for initial access. Over six months and 11 incidents, they targeted IT, industrial, and technology sectors using ransomware variants such as Warlock, LockBit, and Babuk. Their operations involve advanced techniques like zero-day exploitation and repurposing legitimate tools (Velociraptor, VMTools AV killer, Cloudflared) to evade detection and maintain persistence. Executables are often named after victim organizations, indicating targeted attacks. While evidence suggests possible Chinese origins, the group primarily pursues financial gain. The threat poses a medium severity risk but demonstrates capabilities that could escalate impact if defenses are weak. European organizations in critical infrastructure and technology sectors should be vigilant against these tactics.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: velociraptor
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses