logo

Threat Spotlight: Storm-0249 Moves from Mass Phishing to Precision EDR Exploitation

ID: 26120365-8153-56f1-a71f-032ba8002ec8

STIX ID: report--26120365-8153-56f1-a71f-032ba8002ec8

Feed Name: ReliaQuest Blog

Threat Score
78/100

Date Published: 2025-12-09

Date Updated: 2026-04-29

...
...

ReliaQuest details how the initial access broker Storm-0249 has shifted from mass phishing to precision attacks that weaponize trusted processes (notably SentinelOne's SentinelAgentWorker.exe) via DLL sideloading, fileless PowerShell delivery (curl|PowerShell), and Microsoft domain spoofing to establish persistent, hard-to-detect footholds and broker access to ransomware affiliates; the report includes TTP mappings, IOCs (hashes, domains, IPs), and recommended detections and automated response playbooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.