logo

Evolution of the PipeMagic backdoor: from the RansomExx incident to CVE-2025-29824

ID: 0490faaf-7d54-5f82-80cb-b9cb9d45846f

STIX ID: report--0490faaf-7d54-5f82-80cb-b9cb9d45846f

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2025-08-18

Date Updated: 2026-04-29

Author: Sergey Lozhkin, Leonid Bezvershenko, Kirill Korchemny, Ilya Savelyev

...
...

Kaspersky and BI.ZONE jointly analyze PipeMagic — a persistent Windows backdoor observed since 2022 — documenting new 2025 infections in the Middle East and Brazil. The report describes diverse initial access and loader techniques (trojanized utilities, fake ChatGPT client, .mshi via msbuild, DLL hijacking), AES/RC4-encrypted shellcode execution, local named-pipe and localhost network communications, plugin modules for I/O, loaders and injectors, AMSI bypass and LSASS memory dumping (ProcDump) for credential theft, and ties to exploitation of CVE-2025-29824 and RansomExx activity; it concludes with IoCs (hashes, domain, pipe names) for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.