Dissecting PipeMagic: Inside the architecture of a modular backdoor framework
ID: 42d3a7ae-df3a-5e22-bd07-d987908e01f9
STIX ID: report--42d3a7ae-df3a-5e22-bd07-d987908e01f9
Feed Name: Microsoft Security
Microsoft Threat Intelligence analyzed a sophisticated modular backdoor named PipeMagic used by the financially motivated actor Storm-2460 alongside exploitation of CVE-2025-29824 (CLFS elevation of privilege). The report details PipeMagic's architecture (payload/execute/network/unknown doubly linked lists), named-pipe delivery, RC4/aPLib protection, a delegated network module implementing C2 over TCP/WebSocket-like GET requests to a cloud domain, extensive backdoor commands for module management and execution, observed ransomware deployment, mitigation recommendations, and IOCs including file hashes and the C2 domain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
