Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware
Researchers studying cybersecurity have shown how threat actors used a now-patched security hole in Microsoft Windows to spread the PipeMagic malware during RansomExx ransomware assaults.
According to a joint analysis released today by Kaspersky and BI.ZONE, the attacks entail the exploitation of CVE-2025-29824, a privilege escalation vulnerability affecting the Windows Common Log File System (CLFS) that Microsoft fixed in April 2025.
PipeMagic, which can function as a full-fledged backdoor that grants remote access and can carry out a variety of commands on compromised hosts, was initially reported in 2022 as a component of RansomExx ransomware attacks that targeted industrial companies in Southeast Asia.
The threat actors were able to access the target infrastructure by taking ...

