Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign

Storm-2460 PipeMagic exploitation of Windows CLFS

Updated 19.08.2025 20:16
Case score 55
Members 1 First seen 19.08.2025 20:16 Latest activity 19.08.2025 20:16

Overview

**Storm-2460** is actively exploiting **CVE-2025-29824** in **Windows CLFS** and using a modified **ChatGPT Desktop Application** project to deliver **PipeMagic** before ransomware deployment. The activity has been seen against organizations in the **IT**, **financial**, and **real estate** sectors across the **US**, **Europe**, **South America**, and the **Middle East**. Microsoft patched **CVE-2025-29824** in April 2025, but unpatched systems remain exposed. Available evidence does not give a reliable victim count, so the full reach is still unknown.
Latest development

Play ransomware / Storm-2460 CVE-2025-29824 PipeMagic campaign

The initial phase centered on a **zero-day CVE-2025-29824** exploit against **Windows CLFS**, with **Storm-2460** using the bug to gain elevated privileges on unpatched systems. That foothold was paired with **PipeMagic** to prepare ransomware deployment and post-compromise control.

Signals

CVEs/products
Geographic context
Remediation
Status
Threat context

Threat actor context

1 listed

Malware context

2 families

Member happenings

Campaign Play ransomware / Storm-2460 CVE-2025-29824 PipeMagic campaign
Updated 19.08.2025 20:16 Lead Contribution 55
Objective Financial Extortion Campaign Active Patch Patch Available

The **Play ransomware** group (**Storm-2460**) is actively exploiting **CVE-2025-29824** with the **PipeMagic** backdoor to raise privileges and deliver ransomware, increasing risk for unpatched **Windows CLFS** systems. The operation has reached organizations across **multiple sectors and geographies**, including the **IT**, **financial**, and **real estate** sectors in the **US**, **Europe**, **South America**, and the **Middle East**. Initial access uses a modified **ChatGPT Desktop Application** project as an in-memory dropper. The backdoor supports persistence and later-stage movement inside targeted networks.