VORANT. Threat Intelligence Sign in Get the full feed

WSUS RCE flaw abused with Velociraptor abuse

high threat financial-servicestransportationgovernment-nationaltechnology

JSAC2026 Day 2 detailed active exploitation of the WSUS RCE flaw (CVE-2025-59287), a Japan-targeting CoGUI phishing-as-a-service platform, RapperBot's IoT botnet, and Qilin ransomware's attack lifecycle.

JPCERT/CC's JSAC2026 Day 2 recap covered a range of research spanning forensics tooling and active intrusion cases affecting Japanese organizations. Researchers detailed a real incident in which attackers exploited the WSUS remote-code-execution vulnerability (CVE-2025-59287) for initial access against a Japanese company, then abused the legitimate forensic tool Velociraptor as a remote-management/C2 mechanism, deploying it via an MSI installer. Correlation of Velociraptor configuration files, PKI structures, hosting domains, and AWS account names across multiple incidents allowed analysts to attribute several intrusions to the same actor.

Separately, two presentations dissected the China-based CoGUI phishing kit and the Phishing-as-a-Service platform FishingMaster (垂钓大师), which powers large-scale phishing campaigns impersonating Japanese financial, transportation, and government-service brands. After 2025 media exposure the operators rebranded as NX and FA while hardening infrastructure concealment and encryption. A related talk on phishing admin panel construction showed that PhaaS operators (including CoGUI and Oriental Gudgeon) rely on Docker-based rapid deployment and a limited pool of dependent domains/URLs, suggesting takedown of admin panels rather than individual sites as a more effective defense.

Other talks covered RapperBot, an IoT DDoS botnet targeting DVRs/cameras with large infection populations in Taiwan, the US, and Japan, whose C2 activity was linked to March 2025 disruptions on X and attacks on Chinese gaming servers before its operator's arrest; a Silver Fox malspam campaign (Sept–Oct 2025) delivering ValleyRAT and VShell via multi-stage loaders to Japanese targets, marking an apparent expansion beyond its usual China/Taiwan focus; and an overview of Qilin ransomware's attack lifecycle in Japan, where SMEs made up over half of 2025 victims, with initial access via leaked credentials from Telegram/Signal and IABs followed by rapid RMM abuse, exfiltration, and automated encryption of virtual environments.

Mentioned in this report

Vulnerabilities CVE-2025-59287KEV
Threat actors Silver Foxqilin
Malware CoGUIFishingMasterQilinRapperBotVShellValleyRATVelociraptor
Campaigns CoGUIRapperBot

Source reporting: https://blogs.jpcert.or.jp/en/2026/02/jsac2026day2.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free