PipeMagic is a modular Windows backdoor associated with financially motivated ransomware activity, most notably operations linked to Storm-2460 and the RansomExx ecosystem. First observed in 2022, it has remained active through later campaigns in the Middle East and Brazil and has been used as a staging and persistence framework before ransomware deployment. PipeMagic has also been reported in intrusions involving exploitation of SAP NetWeaver and Windows privilege-escalation vulnerabilities, including CVE-2025-29824.
The malware is designed to provide persistent remote access and flexible post-compromise control through a plugin-based architecture. It is commonly deployed in memory and uses named pipes together with a localhost communication mechanism to pass modules and payloads internally. PipeMagic can establish command-and-control communications over TCP, collect host and user information, receive and manage additional modules in memory, execute commands, enumerate processes, delete modules, and remove itself. Reported plugins extend functionality with file I/O handling, payload loading, and .NET execution, including AMSI bypass to facilitate in-memory execution of follow-on payloads.
Observed delivery methods include trojanized software, a fake ChatGPT desktop application used as a lure, malicious help-file based loaders, DLL hijacking, MSBuild abuse, and deployment through web shells after server-side exploitation. Earlier activity also involved exploitation of CVE-2017-0144 for initial access. In ransomware intrusions, operators have used PipeMagic before exploiting local privilege-escalation flaws to obtain SYSTEM privileges and then deploy ransomware. Associated post-exploitation activity has included credential theft via LSASS dumping and actions supporting lateral movement.
Victims have included industrial, IT, financial, real estate, retail, manufacturing, and enterprise environments across Southeast Asia, the Middle East, South America, Europe, and the United States. PipeMagic is notable for its stealth-oriented modular design, in-memory operation, and role as an extensible access platform that supports ransomware operators through persistence, payload delivery, privilege escalation workflows, credential access, and broader post-compromise control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The exploit for this vulnerability was executed by the PipeMagic malware, which we first discovered in December 2022 in a RansomExx ransomware campaign.
The exploit for this vulnerability was executed by the PipeMagic malware, which we first discovered in December 2022 in a RansomExx ransomware campaign.
Ransomware groups and Chinese advanced persistent threat (APT) groups are targeting a critical vulnerability in SAP NetWeaver... The vulnerability, tracked as CVE-2025-31324, has a CVSS score of 10 and affects NetWeaver's Visual Composer development server. Threat actors can exploit the vulnerability using remote attacks to execute arbitrary code without authentication... SAP later confirmed it as an unrestricted file upload vulnerability... allowing attackers to upload malicious files directly to the system without authorization.
RansomEXX, also tracked as Storm-2460, is known for using the modular backdoor named PipeMagic. ReliaQuest observed the deployment of a PipeMagic sample beaconing to a known RansomEXX domain.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft researchers have detailed a modular backdoor framework called “PipeMagic,” used by threat actors to stealthily deploy ransomware.
Microsoft published a lengthy analysis of PipeMagic — a backdoor used by a threat actor they call Storm-2460... Once PipeMagic is running, the threat actor performs the CLFS exploit to escalate privileges before launching their ransomware.
"BianLian and RansomExx Exploit SAP NetWeaver Flaw to Deploy PipeMagic Trojan"
25 distinct techniques documented for this family, organized by ATT&CK tactic.
After decryption, the resulting shellcode is executed via the WinAPI function EnumDeviceMonitor... with the shellcode dynamically resolving their addresses via GetProcAddress.
An example of executing this payload: c:\windows\system32\cmd.exe "/k c:\windows\microsoft.net\framework\v4.0.30319\msbuild.exe c:\windows\help\metafile.mshi"
To hinder analysis, the attackers hashed API functions using the FNV-1a algorithm... the loader contains obfuscated C# code and a very long hexadecimal string.
the attackers used a fake ChatGPT client application as bait... However, it had no user functionality – when launched, it simply displayed a blank screen.
This module, found in one of the infections, is responsible for injecting additional payloads into memory and executing them.
The library deploys the decrypted code into memory and transfers control to it, and the original file is subsequently deleted.
An example of executing this payload: c:\windows\system32\cmd.exe "/k c:\windows\microsoft.net\framework\v4.0.30319\msbuild.exe c:\windows\help\metafile.mshi"
the application extracted a 105,615-byte AES-encrypted array from its code, decrypted it, and executed it... The C# code serves two purposes – decrypting and executing the shellcode... the file contents are decrypted using the symmetric AES cipher in CBC mode
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as part of a related cleanup guide, not as part of the GigaWiper incident itself.
PipeMagic is a backdoor that provides remote access, can operate as a network gateway, supports plugin-based payload delivery and execution, uses named pipes and localhost communication for encrypted payload transfer, and has been observed using multiple loaders including trojanized Rufus, fake ChatGPT applications, .mshi/msbuild execution, and DLL hijacking.
Malware used in intrusion chain for RansomExx ransomware; deployed after exploiting a Windows CLFS privilege escalation flaw (CVE-2025-29824).
Trojan deployed after exploitation of SAP NetWeaver; also reported exploiting a Windows CLFS zero-day to deploy ransomware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.