# Huntress Reports Velociraptor Abuse in Incidents Involving WSUS Exploitation and VS Code Tunnels

DevFeed: [Huntress Reports Velociraptor Abuse in Incidents Involving WSUS Exploitation and VS Code Tunnels](<https://devfeed.tech/articles/velociraptor-misuse-pt-ii-the-eye-of-the-storm-54631.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/velociraptor-misuse-part-two-eye-of-the-storm>)

Author: Harlan Carvey; James Northey; Lindsey O'Donnell-Welch

Published: 2025-12-03T05:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [PowerShell](<https://devfeed.tech/topics/powershell.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Visual Studio Code](<https://devfeed.tech/topics/visual-studio-code.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [include](<https://devfeed.tech/tags/include.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [security](<https://devfeed.tech/tags/security.md>), [visual-studio-code](<https://devfeed.tech/tags/visual-studio-code.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

Huntress reports multiple incidents in which threat actors abused the open-source Velociraptor digital forensics and incident response tool for command-and-control communications. The incidents involved overlapping indicators of compromise and varied attack techniques, including WSUS exploitation, Cloudflare tunnel tokens, encoded PowerShell commands, and VS Code downloads.

## Source excerpt

Huntress reports an uptick in threat actors abusing the Velociraptor open-source DFIR tool, linked to incidents involving WSUS exploitation, VS Code tunnels, and more.