PipeMagic Backdoor Resurfaces as Part of Play Ransomware Attack Chain
ID: 89906fd8-0bff-5b43-9e25-a3dc703049af
STIX ID: report--89906fd8-0bff-5b43-9e25-a3dc703049af
Feed Name: Dark Reading
Date Published: 2025-08-19
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Microsoft and other researchers observed the Storm-2460/Play group exploiting a Windows CLFS zero-day (CVE-2025-29824) to escalate privileges and deploy the PipeMagic modular backdoor—packaged as a fake ChatGPT Desktop app—which fetches modules via named pipes and communicates with C2 to enable persistence, lateral movement, and ransomware deployment; activity has been seen across IT, financial, real estate and manufacturing sectors in multiple regions. Organizations are advised to apply the April patch for CVE-2025-29824, enable Microsoft Defender tamper and network protection, run EDR in block mode, enable automated investigation/remediation, and turn on cloud-delivered protections to reduce exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
