Evolution of the PipeMagic backdoor: from the RansomExx incident to CVE-2025-29824
ID: 0490faaf-7d54-5f82-80cb-b9cb9d45846f
STIX ID: report--0490faaf-7d54-5f82-80cb-b9cb9d45846f
Feed Name: Securelist by Kaspersky
Date Published: 2025-08-18
Date Updated: 2026-04-29
Author: Sergey Lozhkin, Leonid Bezvershenko, Kirill Korchemny, Ilya Savelyev
Kaspersky and BI.ZONE jointly analyze PipeMagic — a persistent Windows backdoor observed since 2022 — documenting new 2025 infections in the Middle East and Brazil. The report describes diverse initial access and loader techniques (trojanized utilities, fake ChatGPT client, .mshi via msbuild, DLL hijacking), AES/RC4-encrypted shellcode execution, local named-pipe and localhost network communications, plugin modules for I/O, loaders and injectors, AMSI bypass and LSASS memory dumping (ProcDump) for credential theft, and ties to exploitation of CVE-2025-29824 and RansomExx activity; it concludes with IoCs (hashes, domain, pipe names) for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
