Storm-2460 logo

Storm-2460

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Ver en IntelTracker → APTTrail →
Storm-2460 is a financially motivated ransomware threat actor that emerged in early 2025. This group is distinguished by its rapid weaponization and exploitation of Windows kernel zero-day vulnerabilities, such as those found in the Common Log File System (CLFS) driver, to achieve privilege escalation and facilitate ransomware deployment. Their operations are characterized by the use of the modular PipeMagic backdoor, which is often disguised as legitimate software, demonstrating a focused, post-compromise strategy to elevate access and deploy their payloads. While some researchers have linked activity to other groups like Play ransomware, Microsoft, the primary source of intelligence on Storm-2460, does not associate the two.
Tecnicas MITRE
T1571 - Non-Standard Port, T1132 - Data Encoding, T1095 - Non-Application Layer Protocol, T1068 - Exploitation for Privilege Escalation, T1543.003 - Windows Service, T1057 - Process Discovery
CVEs relacionadas
CVE-2025-7775, CVE-2025-6558, CVE-2025-53779, CVE-2025-53771, CVE-2025-53770, CVE-2025-53690

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Tipo
apt
Pais origen
RU
Motivacion
-
Impacto
54
Actualizado
Fri, 02 Ja

Sectores objetivo (SOCRadar)

Information ServicesFinanceRental & LeasingRetailSoftware Publishers