logo

Dissecting PipeMagic: Inside the architecture of a modular backdoor framework

ID: 42d3a7ae-df3a-5e22-bd07-d987908e01f9

STIX ID: report--42d3a7ae-df3a-5e22-bd07-d987908e01f9

Feed Name: Microsoft Security

Threat Score
78/100

Date Published: 2025-08-18

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence analyzed a sophisticated modular backdoor named PipeMagic used by the financially motivated actor Storm-2460 alongside exploitation of CVE-2025-29824 (CLFS elevation of privilege). The report details PipeMagic's architecture (payload/execute/network/unknown doubly linked lists), named-pipe delivery, RC4/aPLib protection, a delegated network module implementing C2 over TCP/WebSocket-like GET requests to a cloud domain, extensive backdoor commands for module management and execution, observed ransomware deployment, mitigation recommendations, and IOCs including file hashes and the C2 domain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.