Also known as: tracked as, CVE-2025-29824, Mustang Panda, Secret Blizzard, Google Sheets, personal photos, an, Sandworm, APT34
Storm-2460 has been observed exploiting CVE-2025-29824, a zero-day elevation-of-privilege flaw in the Windows Common Log File System (CLFS), to elevate local privileges inside compromised environments. The actor leverages the native certutil utility to download a malicious MSBuild file from a legitimate website that has been subverted, after which it injects and runs the PipeMagic backdoor entirely in memory. PipeMagic serves as a modular framework that supports multiple payloads, notably ransomware components such as Medusa. Once privilege escalation is achieved, the actor deploys the ransomware to encrypt victim data and leaves a ransom note named !\_READ_ME_REXX2_.txt on infected hosts. In addition, Storm-2460 has shown capability to use other delivery techniques like malicious attachments that employ MSBuild execution, as well as potential supply‑chain compromises. The group’s operational toolkit includes common Windows utilities—PowerShell, rundll32—and third‑party tools such as Cobalt Strike for post‑exploitation command and control. Their malware also exhibits persistence mechanisms via scheduled tasks and DLL injection while attempting to evade detection by modifying registry values and bypassing user account control. Microsoft recommends that organizations prioritize patching the CVE-2025-29824 vulnerability and routinely monitor for anomalous usage of certutil, rundll32, or PowerShell that could indicate a foothold from a PipeMagic backdoor.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm‑2460 is a financially driven threat actor that leveraged the zero‑day CVE‑2025‑29824 in Windows CLFS to achieve privilege escalation and deploy the PipeMagic modular backdoor. They use certutil to download malicious code from compromised legitimate sites, then inject ransomware such as Medusa that encrypts files and drops an unmistakable ransom note. The actor targets a wide range of sectors across North America, Europe, Asia‑Pacific and the Middle East.
Goals & Targeting
Storm‑2460 aims primarily at financial gain through ransomware payments. The actor targets sectors with high-value data and regulatory pressure—including finance, healthcare, energy, defense, and critical infrastructure—across geographies such as the United States, Europe, the Middle East, South America, and parts of Asia‑Pacific. By exploiting a zero‑day Windows kernel flaw and using legitimate system tools for delivery, they achieve quick compromise and stealth, making lucrative targets more likely to succeed and comply with ransom demands.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm‑2460 has maintained activity across multiple wave attacks, typically launching a zero‑day exploitation followed by rapid installation of PipeMagic and ransomware on the same host. Their campaigns have spanned several continents, demonstrating agility in pivoting between different sectors (IT, finance, real estate) within short windows. Observed operational tempo suggests quick compromise-to-cash cycles—often only days from initial intrusion to ransom payment—highlighting a focus on immediate financial payoff rather than long‑term espionage.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is largely grounded in recent Microsoft blog posts (April and August 2025) that describe the CVE-2025‑29824 exploitation and PipeMagic deployment. Alias information is somewhat inconsistent across sources, and there are no publicly available first or last seen timestamps; therefore confidence regarding early activity is moderate but technical details about TTPs are high.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
42
Tools
0
Campaigns
40
IOCs
0
Observed Data
11
Tactics