Velociraptor is a digital forensics and incident response (DFIR) tool that attackers are repurposing for stealthy command-and-control (C2) and ransomware delivery.
Overview
Velociraptor is a digital forensics and incident response (DFIR) tool that attackers are repurposing for stealthy command-and-control (C2) and ransomware delivery. Its abuse as a legitimate tooling component enables covert remote control and payload deployment, increasing evasion potential and complicating detection in security environments.
Related Threat Clusters
-
Warlock Ransomware Group Enhances Attack Techniques with BYOVD and Remote Access Tools
The Warlock ransomware group, also known as Water Manaul, has escalated its attack methods by exploiting unpatched Microsoft SharePoint servers and employing new tactics for persistence and lateral movement. Recent…
5 articles · Updated March 16, 2026 -
Ransomware Tactics Evolve: EDR Killers Expand Beyond Vulnerable Drivers
Recent research from ESET reveals that ransomware attackers are increasingly using EDR killers to disable endpoint detection and response (EDR) systems before launching their encryptors. These tools have become standard…
18 articles · Updated March 19, 2026 -
Multiple Attackers Exploit Unpatched SharePoint Servers, Microsoft Reports
Microsoft's DART team discovered two distinct threat actors operating simultaneously within the same victim network, complicating incident response efforts. The investigation began with ransomware activity linked to…
5 articles · Updated June 23, 2026 -
Hackers Exploit Velociraptor DFIR Tool for C2 and Ransomware Attacks
Hackers are utilizing the Velociraptor DFIR tool to establish stealthy command and control (C2) operations and deploy ransomware. This method enhances their ability to evade detection while executing cyber attacks.…
2 articles · Updated December 4, 2025
Recent Intelligence Reports
- Microsoft Uncovers Parallel Threat Activity From Two Cyberattackers in Single Intrusion — Gbhackers · June 23, 2026
- Unpatched SharePoint servers opened the door to multiple attackers, Microsoft finds — Csoonline · June 23, 2026
- EDR killers explained: Beyond the drivers — Welivesecurity · March 19, 2026
- Warlock Ransomware Group Augments Post — Darkreading · March 17, 2026
- Hackers Leverage Velociraptor DFIR Tool for Stealthy C2 & Ransomware Delivery — Cybersecuritynews · December 4, 2025
- IR Trends Q3 2025: ToolShell attacks dominate, highlighting criticality of segmentation and rapid response — Blog.Talosintelligence · October 23, 2025