Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading
In order to enable ransomware assaults, the threat actor identified as Storm-0249 is probably abandoning its function as an initial access broker in favor of a mix of more sophisticated strategies like domain spoofing, DLL side-loading, and fileless PowerShell execution.
According to a report shared with The Hacker News by ReliaQuest, these techniques provide them the ability to evade defenses, enter networks, sustain persistence, and operate covertly, causing grave worries for security personnel.
Microsoft has given the name Storm-0249 to an initial access broker that has sold access points to other cybercrime groups, such as ransomware and extortion actors like Storm-0501. In September 2024, the IT giant first brought attention to it.
Then, earlier this year, Microsoft also dis...

