PipeMagic is a modular Windows backdoor associated with financially motivated threat actor Storm-2460 and RansomEXX ransomware operations. First discovered in December 2022 during attacks against industrial companies in Southeast Asia, it subsequently appeared in campaigns affecting the Middle East and Brazil. Observed targets include manufacturing, information technology, financial services, retail, real estate, and software organizations.
PipeMagic provides remote access and command execution and supports a network gateway mode. Its architecture uses named pipes and a local communication interface, with TCP-based command-and-control. It receives additional modules over the network and maintains modules in memory, allowing operators to update and extend its functionality. It collects and exfiltrates basic host information, including computer and user names and system specifications. Recovered plugins provide file input/output, additional payload execution, and .NET payload loading with AMSI bypass. The framework supports persistent access and subsequent ransomware deployment.
Delivery chains have used trojanized software, including Rufus and a counterfeit ChatGPT desktop application derived from an open-source project. Other observed execution methods include obfuscated C# loaders, DLL hijacking through a legitimate Google Chrome updater component, and MSBuild abuse. PipeMagic has also been deployed through web shells following exploitation of SAP NetWeaver vulnerability CVE-2025-31324.
PipeMagic-associated campaigns have exploited Windows privilege-escalation vulnerabilities CVE-2025-24983 and CVE-2025-29824. The latter affects the Windows Common Log File System driver and has been executed through PipeMagic to obtain SYSTEM privileges before ransomware deployment. Operators have also used ProcDump to extract LSASS memory for credential theft and to support lateral movement.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This maximum severity unrestricted file upload vulnerability allowed attackers to deploy JSP web shells and execute commands remotely via simple HTTP requests, making it accessible even to attackers with limited technical expertise. | The SAP NetWeaver zero-day (CVE-2025-31324) exemplifies this, as attackers used varied “exploitation twists”—deploying tools like “Brute Ratel” for stealthy command-and-control (C2), the Heaven’s Gate technique for memory manipulation, and persistent backdoors like “PipeMagic.”
CVE-2025-24983 (CVSS skóre 7,0) Použitie odalokovaného miesta v pamäti v rámci Windows Win32 Kernel Subsystem by lokálny autentifikovaný útočník mohol zneužiť na eskaláciu privilégií na úroveň oprávnení SYSTEM. Pozn.: Podľa spoločnosti ESET je predmetná zraniteľnosť aktívne zneužívaná útočníkmi na šírenie malvéru PIPEMAGIC minimálne od marca 2023. | Podľa spoločnosti ESET je predmetná zraniteľnosť aktívne zneužívaná útočníkmi na šírenie malvéru PIPEMAGIC minimálne od marca 2023.
Critical Vulnerability in Windows Common Log File System (CLFS) CVE-2025-29824... Use after free in Windows Common Log File System Driver (CLFS) allows an authorised attacker to elevate privileges locally. Microsoft have identified a threat actor group leveraging this flaw through the PipeMagic malware to gain SYSTEM-level access to perform post-exploitation activities such as credential dumping via LSASS and deploying ransomware. | Microsoft have identified a threat actor group leveraging this flaw through the PipeMagic malware to gain SYSTEM-level access to perform post-exploitation activities such as credential dumping via LSASS and deploying ransomware.
The exploit for this vulnerability was executed by the PipeMagic malware, which we first discovered in December 2022 in a RansomExx ransomware campaign.
RansomEXX, also tracked as Storm-2460, is known for using the modular backdoor named PipeMagic. ReliaQuest observed the deployment of a PipeMagic sample beaconing to a known RansomEXX domain.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft researchers have detailed a modular backdoor framework called “PipeMagic,” used by threat actors to stealthily deploy ransomware.
Microsoft published a lengthy analysis of PipeMagic — a backdoor used by a threat actor they call Storm-2460... Once PipeMagic is running, the threat actor performs the CLFS exploit to escalate privileges before launching their ransomware.
"BianLian and RansomExx Exploit SAP NetWeaver Flaw to Deploy PipeMagic Trojan"
27 distinct techniques documented for this family, organized by ATT&CK tactic.
After decryption, the resulting shellcode is executed via the WinAPI function EnumDeviceMonitor... with the shellcode dynamically resolving their addresses via GetProcAddress.
An example of executing this payload: c:\windows\system32\cmd.exe "/k c:\windows\microsoft.net\framework\v4.0.30319\msbuild.exe c:\windows\help\metafile.mshi"
To hinder analysis, the attackers hashed API functions using the FNV-1a algorithm... the loader contains obfuscated C# code and a very long hexadecimal string.
the attackers used a fake ChatGPT client application as bait... However, it had no user functionality – when launched, it simply displayed a blank screen.
This module, found in one of the infections, is responsible for injecting additional payloads into memory and executing them.
The library deploys the decrypted code into memory and transfers control to it, and the original file is subsequently deleted.
An example of executing this payload: c:\windows\system32\cmd.exe "/k c:\windows\microsoft.net\framework\v4.0.30319\msbuild.exe c:\windows\help\metafile.mshi"
the application extracted a 105,615-byte AES-encrypted array from its code, decrypted it, and executed it... The C# code serves two purposes – decrypting and executing the shellcode... the file contents are decrypted using the symmetric AES cipher in CBC mode
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison relating to suspicious named-pipe communications.
Mentioned only as part of a related cleanup guide, not as part of the GigaWiper incident itself.
PipeMagic is a backdoor that provides remote access, can operate as a network gateway, supports plugin-based payload delivery and execution, uses named pipes and localhost communication for encrypted payload transfer, and has been observed using multiple loaders including trojanized Rufus, fake ChatGPT applications, .mshi/msbuild execution, and DLL hijacking.
Malware used in intrusion chain for RansomExx ransomware; deployed after exploiting a Windows CLFS privilege escalation flaw (CVE-2025-29824).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.