Skip to content

PipeMagic

PipeMagic is a modular Windows backdoor linked to financially motivated ransomware activity attributed by Microsoft to Storm-2460, an actor associated with RansomEXX and also tracked in reporting as the Play ransomware group.

Profile source: Mallory opens in a new tab

PipeMagic

Family profile

PipeMagic is a modular Windows backdoor linked to financially motivated ransomware activity attributed by Microsoft to Storm-2460, an actor associated with RansomEXX and also tracked in reporting as the Play ransomware group. First identified during RansomEXX activity in late 2022, it has subsequently been used against organizations in the Middle East and Brazil and in ransomware intrusions affecting organizations in the Americas, Europe, and the Middle East, including IT, financial, real-estate, retail, software, industrial, and manufacturing sectors.

PipeMagic provides persistent remote access and extensible post-compromise control through dynamically delivered modules. It communicates with command-and-control infrastructure over TCP and uses named pipes for local module delivery and inter-module communications. Its in-memory module management supports payload execution, module updates, module removal, self-deletion, process enumeration, and collection and transmission of host details. Observed and recovered plugins add file I/O, payload loading, execution of 64-bit payloads, and .NET payload execution with AMSI bypass. The framework has been deployed in memory and has masqueraded as a modified ChatGPT desktop application to conceal its malicious function.

PipeMagic has been delivered through several mechanisms, including trojanized software, fake ChatGPT-themed applications, malicious Microsoft Help Index content, MSBuild abuse, and DLL side-loading or hijacking involving a legitimate application component. It has also been deployed after exploitation of SAP NetWeaver vulnerabilities. Storm-2460 has used PipeMagic in attacks exploiting CVE-2025-29824, a Windows CLFS elevation-of-privilege vulnerability, to obtain SYSTEM-level access before ransomware deployment. Associated intrusions have included LSASS credential dumping with renamed ProcDump, anti-forensic activity, persistence, lateral movement, and ransomware execution.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

Reported operators

Threat actors

3 named in public reporting
RansomEXX

Microsoft researchers have detailed a modular backdoor framework called “PipeMagic,” used by threat actors to stealthily deploy ransomware.

Play

Microsoft published a lengthy analysis of PipeMagic — a backdoor used by a threat actor they call Storm-2460... Once PipeMagic is running, the threat actor performs the CLFS exploit to escalate privileges before launching their ransomware.

BianLian

"BianLian and RansomExx Exploit SAP NetWeaver Flaw to Deploy PipeMagic Trojan"

Exploited software

Vulnerabilities linked to PipeMagic

5 CVEs

MITRE ATT&CK

PipeMagic in ATT&CK

27 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.