The Containment Era is here. →Explore

Executive Summary

In October 2025, cybersecurity researchers uncovered that threat actors associated with Storm-2603 (also known as Gold Salem or CL-CRI-1040) leveraged Velociraptor, a legitimate open-source digital forensics and incident response (DFIR) tool, to facilitate a series of LockBit ransomware attacks. Adversaries exploited Velociraptor’s capabilities to gather intelligence and move laterally within target environments, evading detection by blending in with regular security operations. The attacks led to significant data encryption events and operational disruptions, primarily impacting organizations with insufficient internal security segmentation and monitoring.

This incident marks a significant evolution in attacker tradecraft, as it demonstrates that widely trusted security tools—often present for defensive use—can be repurposed as offensive weapons. Increased regulatory scrutiny and the recurrent rise of double extortion ransomware attacks highlight the urgent need for organizations to monitor tool usage and improve east-west visibility.

Why This Matters Now

The abuse of legitimate DFIR tools like Velociraptor in active ransomware campaigns presents a new challenge for defenders, making traditional detection methods insufficient. As adversaries adopt trusted utilities for malicious purposes, it becomes critical for security teams to tighten controls around tool usage, implement real-time traffic monitoring, and enforce zero trust segmentation.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Threat actors used Velociraptor to conduct reconnaissance, move laterally, and maintain persistence, all while evading detection by appearing as legitimate security activity.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust Segmentation, microsegmentation, encrypted traffic enforcement, egress policy controls, and threat detection would have significantly restricted attacker movement, contained the spread of malicious activity, and provided rapid detection. These controls are crucial for preventing unauthorized lateral movement, exfiltration, and the spread of ransomware throughout cloud and hybrid environments.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Blocked unauthorized inbound access and known bad payloads at the perimeter.

Privilege Escalation

Control: Multicloud Visibility & Control

Mitigation: Detected abnormal privilege usage through centralized visibility and alerting.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Restricted unauthorized east-west traffic between workloads and services.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Blocked encrypted or unauthorized outbound C2 communication.

Exfiltration

Control: Encrypted Traffic (HPE)

Mitigation: Detected or blocked unapproved data exfiltration attempts.

Impact (Mitigations)

Provided rapid detection and response to anomalous behavior indicative of mass encryption.

Impact at a Glance

Affected Business Functions

  • IT Operations
  • Data Management
  • Customer Services
Operational Disruption

Estimated downtime: 5 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive customer and operational data due to system compromise.

Recommended Actions

  • Enforce Zero Trust Segmentation to tightly control east-west workload communications and block lateral movement by default.
  • Implement robust egress policy enforcement to monitor and restrict outbound traffic, disrupting command and control and exfiltration channels.
  • Deploy centralized, multi-cloud visibility with real-time anomaly detection to rapidly identify suspicious privilege escalation and remote tool abuse.
  • Utilize encrypted traffic inspection for all internal and external flows to detect unauthorized or covert data transfers.
  • Continuously update cloud firewall and inline IPS policies to block known threats and ensure least-privilege network access throughout the environment.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image