Tag: PipeMagic Trojan

BianLian and RansomExx Exploit SAP NetWeaver Flaw to Deploy PipeMagic Trojan
News

BianLian and RansomExx Exploit SAP NetWeaver Flaw to Deploy PipeMagic Trojan

A recently revealed security vulnerability in SAP NetWeaver, tagged as CVE-2025-31324, is reportedly being used by at least two distinct cybercrime organizations, BianLian and RansomExx. This suggests that several threat actors are abusing the vulnerability. In a new report released today, cybersecurity company ReliaQuest said it has found evidence of involvement from the RansomExx ransomware family, which Microsoft tracks under the name Storm-2460, and the BianLian data extortion crew. Based on infrastructure ties to IP addresses previously identified as belonging to the e-crime organization, BianLian is evaluated as having been involved in at least one event. According to the company, we found a server at 184[.]174[.]96[.]74 that was providing reverse proxy services that were s...
PipeMagic Trojan Exploits Windows Zero-Day Vulnerability to Deploy Ransomware
News

PipeMagic Trojan Exploits Windows Zero-Day Vulnerability to Deploy Ransomware

Microsoft has disclosed that ransomware attacks targeting a limited number of targets exploited a now-patched security hole affecting the Windows Common Log File System (CLFS) as a zero-day vulnerability. The computer giant claimed the targets include companies in the US IT and real estate industries, the Venezuelan banking sector, a Spanish software company, and the Saudi Arabian retail industry. It is possible to obtain SYSTEM rights by exploiting the privilege escalation bug in CLFS, CVE-2025-29824. Redmond corrected problem as part of its April 2025 Patch Tuesday update. Under the alias Storm-2460, Microsoft is monitoring the activity and post-compromise exploitation of CVE-2025-29824. The threat actors are also using a piece of malware called PipeMagic to distribute the expl...