Storm-0249 Abuses EDR Processes in Stealthy Attacks
ID: 0ffe52db-bd7d-57ff-9476-912b99cffbcd
STIX ID: report--0ffe52db-bd7d-57ff-9476-912b99cffbcd
Feed Name: Dark Reading
Storm-0249, an initial access broker, has pivoted from noisy phishing to precision, loader-centric campaigns that weaponize legitimate EDR processes and built-in Windows utilities. Using a ClickFix social-engineering lure to execute spoofed MSIs, the actor sideloads trojanized DLLs alongside legitimate EDR binaries to achieve SYSTEM-level execution and persistence, and leverages LOLBins (e.g., curl.exe) to pipe fileless PowerShell into memory for stealthy post-compromise activity. ReliaQuest recommends behavioral analytics, EDR baselining, DNS monitoring, strict LOLBin restrictions, network segmentation, and automated response playbooks to mitigate these tactics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
