Storm-2460 is an unidentified threat actor known for deploying PipeMagic ransomware via elevation of privilege vulnerabilities.
Analyst brief
Storm-2460 is an unidentified threat actor that exploits elevation of privilege vulnerabilities to deploy PipeMagic malware and ransomware. The actor targets vulnerable systems to escalate access within compromised environments. Key TTPs include the exploitation of privilege escalation flaws, use of the certutil utility to download malware from compromised legitimate third-party websites, and file encryption with a ransom note named !_READ_ME_REXX2_!.txt. Defenders should prioritize patching elevation of privilege vulnerabilities and monitor for suspicious use of native tools like certutil.
Storm-2460
unknown
Storm-2460 is a threat actor that has exploited elevation of privilege vulnerabilities to deploy PipeMagic malware and ransomware, enabling them to escalate access within compromised environments. They have been observed using the certutil utility to download malware from compromised legitimate third-party websites. Ransomware activity associated with Storm-2460 includes file encryption and the deployment of a ransom note named !_READ_ME_REXX2_!.txt. Microsoft recommends prioritizing security updates for elevation of privilege vulnerabilities to mitigate the impact of this actor's activities.