Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-2460

Also known as: tracked as, CVE-2025-29824, Mustang Panda, Secret Blizzard, Google Sheets, personal photos, an, Sandworm, APT34

Description

Storm-2460 has been observed exploiting CVE-2025-29824, a zero-day elevation-of-privilege flaw in the Windows Common Log File System (CLFS), to elevate local privileges inside compromised environments. The actor leverages the native certutil utility to download a malicious MSBuild file from a legitimate website that has been subverted, after which it injects and runs the PipeMagic backdoor entirely in memory. PipeMagic serves as a modular framework that supports multiple payloads, notably ransomware components such as Medusa. Once privilege escalation is achieved, the actor deploys the ransomware to encrypt victim data and leaves a ransom note named !\_READ_ME_REXX2_.txt on infected hosts. In addition, Storm-2460 has shown capability to use other delivery techniques like malicious attachments that employ MSBuild execution, as well as potential supply‑chain compromises. The group’s operational toolkit includes common Windows utilities—PowerShell, rundll32—and third‑party tools such as Cobalt Strike for post‑exploitation command and control. Their malware also exhibits persistence mechanisms via scheduled tasks and DLL injection while attempting to evade detection by modifying registry values and bypassing user account control. Microsoft recommends that organizations prioritize patching the CVE-2025-29824 vulnerability and routinely monitor for anomalous usage of certutil, rundll32, or PowerShell that could indicate a foothold from a PipeMagic backdoor.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Healthcare
Education
Non profit
Maritime
Energy
Utilities
Information technology
Manufacturing
Transportation
Critical infrastructure
Media
Think tank
Aviation
Legal services

Targeted Countries / Regions

CN
US
RU
TW
UA
GB
RO
IR
NL
FR
KP
CA
MX
IN
DE
ES
IT
JP
BR
SA
PK

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

Storm‑2460 is a financially driven threat actor that leveraged the zero‑day CVE‑2025‑29824 in Windows CLFS to achieve privilege escalation and deploy the PipeMagic modular backdoor. They use certutil to download malicious code from compromised legitimate sites, then inject ransomware such as Medusa that encrypts files and drops an unmistakable ransom note. The actor targets a wide range of sectors across North America, Europe, Asia‑Pacific and the Middle East.

Goals & Targeting

Storm‑2460 aims primarily at financial gain through ransomware payments. The actor targets sectors with high-value data and regulatory pressure—including finance, healthcare, energy, defense, and critical infrastructure—across geographies such as the United States, Europe, the Middle East, South America, and parts of Asia‑Pacific. By exploiting a zero‑day Windows kernel flaw and using legitimate system tools for delivery, they achieve quick compromise and stealth, making lucrative targets more likely to succeed and comply with ransom demands.

Enhanced Description

Key Capabilities

  • Zero‑day exploitation of CLFS (CVE-2025-29824) to gain local privilege escalation
  • Use of native Windows utilities such as certutil and rundll32 for file download and execution
  • Deployment of the modular PipeMagic backdoor with built‑in ransomware components like Medusa
  • Persistence via scheduled tasks, custom services, DLL hijacking and modification of registry keys
  • Lateral movement through WMI queries, Remote Desktop, and DLL injection (T1574.001)
  • Credential theft using keyloggers, LSASS memory extraction, and credential dumping tools
  • Defense evasion by bypassing UAC, disabling logging and file‑deletion techniques
  • Data exfiltration and C2 via PowerShell scripts and custom protocols

MITRE ATT&CK Tactics

Execution
Privilege Escalation
Persistence
Defense Evasion
Credential Access
Discovery
Exfiltration
Impact

ATT&CK Techniques

T1068
T1087.002
T1047
T1059.001
T1059.003
T1053.005
T1105
T1112
T1548.002
T1548.003
T1078
T1204.002
T1566.001
T1574.001

Software / Tooling

PipeMagic
Medusa Ransomware
Cobalt Strike
Quasar RAT
rundll32
certutil
PowerShell

Campaigns & Victims

Storm‑2460 has maintained activity across multiple wave attacks, typically launching a zero‑day exploitation followed by rapid installation of PipeMagic and ransomware on the same host. Their campaigns have spanned several continents, demonstrating agility in pivoting between different sectors (IT, finance, real estate) within short windows. Observed operational tempo suggests quick compromise-to-cash cycles—often only days from initial intrusion to ransom payment—highlighting a focus on immediate financial payoff rather than long‑term espionage.

IOC Patterns

  • Spearphishing attachment containing an MSBuild payload hosted from a compromised legitimate website
  • Use of certutil command line for downloading malicious binaries
  • In-memory execution via rundll32 or PowerShell after CLFS privilege escalation
  • Deployment of PipeMagic backdoor with modular ransomware modules (e.g., Medusa)
  • Ransomware note named !\_READ_ME_REXX2_.txt on victim machines

Recommended Actions

  • Apply the security update that patches CVE-2025-29824 immediately
  • Disable or harden CLFS logging features to reduce exploitation surface area
  • Block or strictly monitor certutil usage in corporate environments (whitelisting policies)
  • Implement detection of rundll32 and PowerShell scripts that load DLLs from temporary paths
  • Enable user‑account control auditing and restrict local privilege escalation rights
  • Use endpoint protection with memory‑detection capabilities against known PipeMagic signatures
  • Establish and test ransomware containment playbooks, including backup isolation and network segmentation

Suggested Tags

APT
ransomware
financial-motive
zero-day
Windows
critical-infrastructure-target
supply-chain-compromise

Confidence Assessment

The analysis is largely grounded in recent Microsoft blog posts (April and August 2025) that describe the CVE-2025‑29824 exploitation and PipeMagic deployment. Alias information is somewhat inconsistent across sources, and there are no publicly available first or last seen timestamps; therefore confidence regarding early activity is moderate but technical details about TTPs are high.

ATT&CK Techniques

Command & Control
1 technique
Impact
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: Mustang Panda
  2. cert.europa.eu — Cited by web research for: Secret Blizzard
  3. attack.mitre.org — Cited by web research for: Sandworm
  4. research.splunk.com — Cited by web research for: T1685
  5. research.splunk.com — Cited by web research for: BlackByte
  6. www.microsoft.com — Cited by web research for: Information Technology
  7. cloud.google.com — Cited by web research for: Legal Services
  8. https://www.microsoft.com/en-us/security/blog/2025/04/08/exploitation-of-clfs-zero-day-leads-to-ransomware-activ — Cited by AI analysis.
  9. https://cyberscoop.com/microsoft-patch-tuesday-april-2025/ — Cited by AI analysis.
  10. https://www.microsoft.com/en-us/security/blog/2025/08/18/dissecting-pipemagic-inside-the-architecture-of-a- — Cited by AI analysis.

Intel Summary

40

Techniques

42

Tools

0

Campaigns

40

IOCs

0

Observed Data

11

Tactics

Tags

Ransomware
Supply Chain Attack
APT
ransomware
financial-motive
zero-day
Windows
critical-infrastructure-target
supply-chain-compromise

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.