#PipeMagic
A ChatGPT App Is Hiding a Backdoor: Microsoft Exposes the PipeMagic Malware
A ChatGPT App Is Hiding a Backdoor: Microsoft Exposes the PipeMagic Malware
Microsoft has exposed PipeMagic, a new backdoor disguised as a ChatGPT app. It was used with a zero-day exploit to gain SYSTEM privileges and deploy ransomware.
securityonline.info
August 20, 2025 at 11:01 AM
#ESETresearch has discovered a zero day exploit abusing #CVE-2025-24983 vulnerability in Windows Kernel to elevate privileges (#LPE). First seen in the wild in March 2023, the exploit was deployed through #PipeMagic backdoor on the compromised machines. 1/4
March 11, 2025 at 5:15 PM
NEW 🚨 Microsoft warns hackers used a fake ChatGPT desktop app to deliver the PipeMagic backdoor, linked to ransomware attacks exploiting a #Windows zero-day.

🔗 hackread.com/fake-chatgpt-desktop-app-pipemagic-backdoor-microsoft/

#CyberSecurity #Microsoft #ChatGPT #PipeMagic #Malware
Fake ChatGPT Desktop App Delivering PipeMagic Backdoor, Microsoft
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
August 18, 2025 at 6:46 PM
PipeMagic is a sophisticated malware framework with a modular, stealthy, and highly extensible architecture, giving threat actors granular control over code execution and making detection and analysis challenging. msft.it/63321spbNh
Dissecting PipeMagic: Inside the architecture of a modular backdoor framework
A comprehensive technical deep dive on PipeMagic, a highly modular backdoor used by Storm-2460 masquerading as a legitimate open-source ChatGPT Desktop Application. Beneath its disguise, PipeMagic is a sophisticated malware framework designed for flexibility and persistence. Once deployed, it can dynamically execute payloads while maintaining robust command and control (C2) communication via a dedicated networking module.
msft.it
August 18, 2025 at 3:27 PM
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware
thehackernews.com
August 18, 2025 at 8:14 PM
The highly modular backdoor PipeMagic and the RaaS offering Medusa both exemplify how threats continuously evolve. The latest Microsoft Threat Intelligence Podcast episode features a threat landscape update with a deep dive on these threats: msft.it/63322s0k2o
Threat Landscape Update: Ransomware-as-a-Service and Advanced Modular Malware
In this episode of the Microsoft Threat Intelligence Podcast, host⁠ ⁠⁠⁠Sherrod DeGrippo⁠ is joined by Tori Murphy, Anna Seitz, and Chuong Dong to break down two threats: the modular backdoor PipeMagic and Medusa ransomware. They discuss how PipeMagic disguises itself as a ChatGPT desktop app to deliver malware, its sophisticated modular design, and what defenders can do to detect it. The team also explores Medusa’s evolution into a ransomware-as-a-service model, its use of double extortion tactics, and the broader threat landscape shaped by ransomware groups, social engineering, and the abuse of legitimate tools.
msft.it
October 8, 2025 at 5:09 PM
PipeMagic is attributed to the financially motivated actor Storm-2460. Because PipeMagic is modular, the threat actor can send module code over the network and the backdoor self-updates in memory. Read about PipeMagic and its internal architecture: msft.it/63328s0k74
October 8, 2025 at 5:10 PM
🟢 The PipeMagic backdoor is active again and exploiting new vulnerabilities

🗨️ Experts from Kaspersky Lab and BI.ZONE have warned about the activity of the PipeMagic backdoor. Kaspersky Lab notes…

#news
The PipeMagic backdoor is active again and exploiting new vulnerabilities
Read more
hackmag.com
March 19, 2026 at 9:40 AM
Microsoft Threat Intelligence has attributed PipeMagic to the financially motivated threat actor Storm-2460, who leveraged the backdoor in targeted attacks to exploit the CVE-2025-29824 EoP vulnerability in CLFS and deploy ransomware.
August 18, 2025 at 3:27 PM
A bit disappointing for Windows 10 users this Patch Tuesday, who seem to be treated like second-class citizens.

This is an exploit under widespread attack and the Storm-2460 scumbags are using this for PipeMagic ransomware. Hopefully the patch comes soon.
Patch Tuesday fixes an exploited bug, but not for Windows 10
Patch Tuesday: A novel way to encourage upgrades? Microsoft would never stoop so low
www.theregister.com
April 9, 2025 at 4:17 AM
SEO poisoning ➡️ Fake RVTools ➡️ Python backdoor ➡️ PipeMagic ➡️ CVE-2025-29824 ➡️ #Ransomexx — domain-wide in <19 hrs.

The Python backdoor connected to azure-secure-agent[.]com (87.251.67[.]241), enabling cmd/PowerShell exec, payload download, screenshots, and IP discovery.
February 19, 2026 at 2:51 PM
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware ift.tt/CwK9ksL
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware
PipeMagic exploits CVE-2025-29824 in Windows, enabling RansomExx attacks in Saudi Arabia and Brazil.
buff.ly
August 18, 2025 at 10:12 PM
Windows zero-day CVE-2025-29824 exploited via PipeMagic malware escalated SYSTEM privileges, leading to targeted ransomware attacks.
PipeMagic Trojan Exploits Windows Zero-Day Vulnerability to Deploy Ransomware
thehackernews.com
April 9, 2025 at 1:39 PM
Threat Actors Abuse Microsoft Help Index File to Execute PipeMagic Malware
Threat Actors Abuse Microsoft Help Index File to Execute PipeMagic Malware
cybersecuritynews.com
August 19, 2025 at 5:22 AM
Windows zero-day CVE-2025-29824 exploited via PipeMagic malware escalated SYSTEM privileges, leading to targeted ransomware attacks.
PipeMagic Trojan Exploits Windows Zero-Day Vulnerability to Deploy Ransomware
thehackernews.com
April 10, 2025 at 6:11 PM
CVE-2025-29824, a CLFS zero-day, enabled Storm-2460's PipeMagic ransomware. Patches (April 8, 2025) address privilege escalation. IT, finance, real estate, and retail sectors globally affected. Use Microsoft Defender and apply updates.#PipeMagicRansomware
April 9, 2025 at 6:15 PM
#Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware

Researchers have lifted the lid on the threat actors' exploitation of a now-patched security flaw in #Windows to deploy the PipeMagic #malware in RansomExx #ransomware attacks!

thehackernews.com/2025/08/micr...
Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware
PipeMagic exploits CVE-2025-29824 in Windows, enabling RansomExx attacks in Saudi Arabia and Brazil.
thehackernews.com
August 18, 2025 at 9:08 PM
Pipemagic: troyano que explota una vulnerabilidad ZeroDays en Windows para implementar el ransomware RansomExx
Pipemagic: troyano que explota una vulnerabilidad ZeroDays en Windows para implementar el ransomware RansomExx
blog.segu-info.com.ar
August 19, 2025 at 4:54 AM
The Microsoft Threat Intelligence team report on PipeMagic, a modular backdoor framework used by Storm-2460. Findings from their analysis include ransomware deployment & delivery via a trojanized ChatGPT desktop application targeting varied sectors worldwide. www.microsoft.com/en-us/securi...
August 19, 2025 at 8:59 AM
Windows Zero-Day Under Fire PipeMagic Trojan Delivers Ransomware Payload.
Microsoft patched a critical flaw (CVE-2025-29824) in the Windows CLFS driver that was actively used in targeted ransomware attacks. Threat actors used a PipeMagic trojan, delivered via a malicious MSBuild script.
April 15, 2025 at 11:34 PM