Skip to content Skip to sidebar Skip to footer

Threat Actors Leveraging SolarWinds Web Help Desk

Microsoft’s security team has observed that attackers are actively targeting publicly accessible instances of SolarWinds Web Help Desk (WHD) to establish footholds in corporate environments and progress deeper into networks.

According to Microsoft Defender researchers, the intrusions began with adversaries exploiting exposed WHD servers to execute code remotely without needing valid credentials. Once inside, they moved laterally across the network in pursuit of systems and data of higher value.

In the observed incidents — dating back to December 2025 — it isn’t yet clear which specific security flaws were leveraged to gain initial entry. The affected systems were vulnerable to both recently disclosed critical bugs, such as CVE-2025-40551 (a high-severity remote code execution issue) and CVE-2025-40536 (a security bypass weakness), as well as an earlier flaw tracked as CVE-2025-26399. Because the servers were susceptible to all three, analysts cannot definitively attribute the starting exploit to a single vulnerability.

Once attackers gained control of a WHD instance, they were able to run arbitrary commands and use the compromised service to launch PowerShell processes. These processes utilized Windows components like the Background Intelligent Transfer Service (BITS) to retrieve and execute additional payloads.

Following initial exploitation, the threat actors deployed legitimate remote management tools — such as Zoho ManageEngine components — as well as other software to maintain persistence and enable more extensive control over the environment.

Microsoft’s analysts highlighted that, in one case, attackers performed Active Directory reconnaissance and even executed advanced techniques like DCSync attacks against domain controllers to extract sensitive credentials.

Security teams are urging organizations running SolarWinds WHD to ensure systems are updated with the latest patches, remove unauthorized remote monitoring installations, rotate credentials, and isolate any compromised machines to curtail risk.

    “Hackers don’t break in — they log in.” 🔐

    Davin Swart

    Go to Top