logo

Storm-0249 Abuses EDR Processes in Stealthy Attacks

ID: 0ffe52db-bd7d-57ff-9476-912b99cffbcd

STIX ID: report--0ffe52db-bd7d-57ff-9476-912b99cffbcd

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-12-10

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Storm-0249, an initial access broker, has pivoted from noisy phishing to precision, loader-centric campaigns that weaponize legitimate EDR processes and built-in Windows utilities. Using a ClickFix social-engineering lure to execute spoofed MSIs, the actor sideloads trojanized DLLs alongside legitimate EDR binaries to achieve SYSTEM-level execution and persistence, and leverages LOLBins (e.g., curl.exe) to pipe fileless PowerShell into memory for stealthy post-compromise activity. ReliaQuest recommends behavioral analytics, EDR baselining, DNS monitoring, strict LOLBin restrictions, network segmentation, and automated response playbooks to mitigate these tactics.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.