Microsoft researchers have detailed a modular backdoor framework called “PipeMagic,” used by threat actors to stealthily deploy ransomware.
PipeMagic
PipeMagic is a modular Windows backdoor linked to financially motivated ransomware activity attributed by Microsoft to Storm-2460, an actor associated with RansomEXX and also tracked in reporting as the Play ransomware group.
Profile source: Mallory opens in a new tabPipeMagic
Family profile
PipeMagic is a modular Windows backdoor linked to financially motivated ransomware activity attributed by Microsoft to Storm-2460, an actor associated with RansomEXX and also tracked in reporting as the Play ransomware group. First identified during RansomEXX activity in late 2022, it has subsequently been used against organizations in the Middle East and Brazil and in ransomware intrusions affecting organizations in the Americas, Europe, and the Middle East, including IT, financial, real-estate, retail, software, industrial, and manufacturing sectors.
PipeMagic provides persistent remote access and extensible post-compromise control through dynamically delivered modules. It communicates with command-and-control infrastructure over TCP and uses named pipes for local module delivery and inter-module communications. Its in-memory module management supports payload execution, module updates, module removal, self-deletion, process enumeration, and collection and transmission of host details. Observed and recovered plugins add file I/O, payload loading, execution of 64-bit payloads, and .NET payload execution with AMSI bypass. The framework has been deployed in memory and has masqueraded as a modified ChatGPT desktop application to conceal its malicious function.
PipeMagic has been delivered through several mechanisms, including trojanized software, fake ChatGPT-themed applications, malicious Microsoft Help Index content, MSBuild abuse, and DLL side-loading or hijacking involving a legitimate application component. It has also been deployed after exploitation of SAP NetWeaver vulnerabilities. Storm-2460 has used PipeMagic in attacks exploiting CVE-2025-29824, a Windows CLFS elevation-of-privilege vulnerability, to obtain SYSTEM-level access before ransomware deployment. Associated intrusions have included LSASS credential dumping with renamed ProcDump, anti-forensic activity, persistence, lateral movement, and ransomware execution.
Capabilities
- Defense Evasion
- Dll Sideloading
- Exfiltration
- Lateral Movement
- Persistence
- Post Exploitation
- Privilege Escalation
- Reconnaissance
Reported operators
Threat actors
3 named in public reportingMicrosoft published a lengthy analysis of PipeMagic — a backdoor used by a threat actor they call Storm-2460... Once PipeMagic is running, the threat actor performs the CLFS exploit to escalate privileges before launching their ransomware.
"BianLian and RansomExx Exploit SAP NetWeaver Flaw to Deploy PipeMagic Trojan"
Exploited software
Vulnerabilities linked to PipeMagic
5 CVEsMITRE ATT&CK