Threat Spotlight: Storm-0249 Moves from Mass Phishing to Precision EDR Exploitation
ID: 26120365-8153-56f1-a71f-032ba8002ec8
STIX ID: report--26120365-8153-56f1-a71f-032ba8002ec8
Feed Name: ReliaQuest Blog
ReliaQuest details how the initial access broker Storm-0249 has shifted from mass phishing to precision attacks that weaponize trusted processes (notably SentinelOne's SentinelAgentWorker.exe) via DLL sideloading, fileless PowerShell delivery (curl|PowerShell), and Microsoft domain spoofing to establish persistent, hard-to-detect footholds and broker access to ransomware affiliates; the report includes TTP mappings, IOCs (hashes, domains, IPs), and recommended detections and automated response playbooks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
