Cybersecurity firms have today revealed a heightened wave of attacks exploiting a now‑patched Windows vulnerability to deploy the modular PipeMagic malware in support of RansomExx ransomware operations across Saudi Arabia and Brazil.
The exploited flaw—identified as CVE‑2025‑29824—is a privilege escalation vulnerability within the Windows Common Log File System (CLFS). Although resolved by Microsoft in April 2025, the flaw has now been weaponized. Kaspersky and BI.ZONE, acting jointly, issued a detailed report confirming the renewed use of this vulnerability and describing how attackers have built a sophisticated attack chain on its foundation.
Sneaky Entry via SMB and Fake ChatGPT App
Attackers used a multi-step intrusion vector: they initially exploited the infamous CVE‑2017‑0144, the SMB remote code execution flaw (also behind the notorious WannaCry outbreak), to gain foothold in targeted systems. In Saudi Arabia, these campaigns began as early as October 2024, leveraging a bogus OpenAI ChatGPT app to lure victims into executing malicious attachments.
Inside the Attack: PipeMagic’s Modular Precision
Once inside, PipeMagic takes over. Researchers describe the malware’s unique capabilities:
- Named pipe communication: PipeMagic creates a named pipe using a random 16‑byte hex string formatted like
\\.\pipe\1.<hex string>. A thread continuously creates, reads from, then destroys that pipe to transmit encrypted payloads and notifications. - Loader hosted on Azure: The malware operates modularly. The loader is disguised as a Microsoft Help Index file (
metafile.mshi) and is hosted on Microsoft Azure. This setup unpacks C# code that decrypts and executes embedded shellcode tailored for 32‑bit Windows systems. - Malicious DLL masquerading as Chrome update: Among the techniques, attackers use DLL hijacking—deploying a malicious DLL named
googleupdate.dll, mimicking a Google Chrome updater. It ensures stealthy, legitimate‑looking execution.
Following successful load and execution, PipeMagic enables:
- File operations,
- Injection of additional payloads,
- Plugin-based modular execution (loader, injector modules).
This adaptability supports ongoing data theft and ransomware deployment, particularly targeting entities in Saudi Arabia and Brazil, where the malware remains active and continues evolving.
Global Implications and Call to Action
Though the immediate campaigns are regionally focused, this aggressive exploitation underscores a broader threat: even patched vulnerabilities can be resurrected and weaponized if systems remain unpatched or compromised via older flaws like SMB. The PipeMagic campaign serves as a stark reminder that attackers link multiple vulnerabilities to build effective, persistent threats.
Organizations should ensure:
- Systems are fully patched, including CLFS and SMB vulnerabilities.
- Robust intrusion detection is in place—monitor for abnormal pipe activity and suspicious Azure-hosted payload downloads.
- Awareness of phishing and fake apps, especially impersonators of trending services like AI tools.
As PipeMagic continues to evolve, particularly via its plugin-based design, cybersecurity resilience hinges on swift patching, careful network monitoring, and user education to avoid infection vectors disguised as legitimate applications.
Please subscribe to the Newsletter so that you do not miss any critical update
