Executive Summary
In June 2025, cybersecurity researchers reported a sophisticated incident in which attackers abused the open-source forensic tool Velociraptor to deploy Visual Studio Code on compromised endpoints and establish an encrypted command-and-control (C2) channel. Threat actors leveraged the legitimate forensic software as a Living Off The Land Binary (LOLBin) to evade detection, achieve execution, and enable covert lateral movement within enterprise environments. This innovative TTP circumvented traditional perimeter detections, and resulted in unauthorized access to sensitive internal systems, raising concerns over the misuse of trusted IT tools in targeted intrusions and potential data exfiltration.
The incident highlights a growing trend of blending legitimate IT and developer software within attack chains, making malicious activity harder to distinguish from normal operations. Organizations face increasing regulatory and operational pressure to implement robust east-west traffic monitoring, behavioral detection, and zero trust controls as attackers adopt stealthier methods.
Why This Matters Now
This attack showcases the urgent threat posed by adversaries abusing trusted IT tools as part of advanced living-off-the-land strategies. As visibility into internal network activity becomes more difficult with the use of legitimate tools, organizations must rapidly enhance segmentation, monitoring, and response capabilities to address these evolving risks.
Attack Path Analysis
The attacker initially compromised a cloud workload by deploying the Velociraptor forensic tool, likely abusing legitimate remote management or credentials. They escalated privileges by leveraging Velociraptor to execute further malicious commands, including downloading Visual Studio Code as a living-off-the-land tool. Using these tools, the adversary moved laterally to other systems or containers within the cloud environment, evading traditional defenses. They established command and control channels over encrypted or covert channels, using Visual Studio Code to tunnel outbound traffic for remote access. Data exfiltration was attempted through these tunnels, leveraging egress routes to siphon information covertly. The attack culminated in potential impacts, such as persistence, tampering, or enabling ransomware or business disruption if not contained.
Kill Chain Progression
Initial Compromise
Description
Adversary gained access to a cloud workload by deploying the Velociraptor tool, likely via compromised credentials or abuse of legitimate remote management software.
Related CVEs
CVE-2025-6264
CVSS 9.8A privilege escalation vulnerability in Velociraptor allows users with COLLECT_CLIENT permissions to execute arbitrary commands and potentially take control of affected endpoints.
Affected Products:
Rapid7 Velociraptor – 0.73.4.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Signed Binary Proxy Execution
System Services
Native API
User Execution
Web Protocols
Command and Scripting Interpreter: Windows Command Shell
Remote Access Software
Masquerading
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Implement automated mechanisms for log review
Control ID: 10.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 9
CISA Zero Trust Maturity Model 2.0 – Continuous Monitoring and Visibility
Control ID: Visibility and Analytics: Advanced
NIS2 Directive – Incident Detection and Response
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer/Network Security
Living off the land attacks using Velociraptor forensic tools create trust exploitation risks, requiring enhanced threat detection and anomaly response capabilities.
Information Technology/IT
Visual Studio Code C2 tunneling through legitimate tools bypasses traditional security controls, demanding zero trust segmentation and egress policy enforcement.
Financial Services
Encrypted traffic abuse and east-west lateral movement threats require multicloud visibility, inline IPS protection, and compliance with regulatory frameworks.
Health Care / Life Sciences
HIPAA compliance violations from covert C2 channels necessitate secure hybrid connectivity, threat detection systems, and encrypted traffic monitoring solutions.
Sources
- Attackers Abuse Velociraptor Forensic Tool to Deploy Visual Studio Code for C2 Tunnelinghttps://thehackernews.com/2025/08/attackers-abuse-velociraptor-forensic.htmlVerified
- Velociraptor incident response tool abused for remote accesshttps://news.sophos.com/en-us/2025/08/26/velociraptor-incident-response-tool-abused-for-remote-access/Verified
- CISA Alerts on Active Exploitation of Rapid7 Velociraptor Vulnerability in Ransomware Attackshttps://cyberpress.org/cisa-alerts-on-active-exploitation-of-rapid7-velociraptor-vulnerability/Verified
- Velociraptor Forensic Tool Used to Deploy LockBit and Babuk Ransomwarehttps://hackmag.com/news/velociraptor-attacksVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
This incident underscores the necessity of Zero Trust controls such as east-west segmentation, workload and container isolation, egress policy enforcement, and continuous threat detection. CNSF-aligned network segmentation, egress filtering, and inline threat prevention would have substantially reduced the attack surface and visibility for the adversary during each phase.
Control: Zero Trust Segmentation
Mitigation: Workload and namespace isolation would have limited adversary access and initial tool deployment.
Control: Threat Detection & Anomaly Response
Mitigation: Unusual process execution and privilege changes are rapidly detected and flagged for response.
Control: East-West Traffic Security
Mitigation: Lateral movement blocked through enforced policy, preventing attacker traversal to other systems.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound tunneling attempts are denied or suspicious channels detected and terminated.
Control: Encrypted Traffic (HPE)
Mitigation: Sensitive data in transit is continuously monitored; unsanctioned unencrypted or anomalous flows are prevented.
Real-time visibility and centralized policy swiftly uncover attacker persistence and automate containment.
Impact at a Glance
Affected Business Functions
- Endpoint Monitoring
- Incident Response
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive endpoint data due to unauthorized access and control.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce zero trust segmentation and microsegmentation to minimize attack surface and prevent unauthorized lateral movement.
- • Implement rigorous egress policy controls and traffic filtering to block command & control tunneling and exfiltration attempts.
- • Deploy inline threat detection and behavioral anomaly response to identify living-off-the-land techniques and misuse of administrative tools.
- • Increase east-west traffic visibility and apply encryption to all sensitive data flows to reduce the effectiveness of covert channels.
- • Maintain centralized, real-time cloud visibility and automated policy enforcement to detect and respond to advanced attacks rapidly.



