Scworld Storm-0249 Exploits EDRs for Covert Malware Attacks
Article Content
Browse articles
Initial access broker Storm-0249 is exploiting endpoint detection and response solutions, specifically SentinelOne, to execute stealthy malware attacks. The group has shifted from mass phishing tactics to more advanced methods, utilizing malicious curl commands and PowerShell scripts to gain SYSTEM privileges and establish persistence for ransomware operations.
Ask AI about this cluster
Answers cite the sources they use
Updated 200d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track Alphv and SentinelOne in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
RansomHouse Targets Namibian Defence Ministry in Cyberattack The Namibia Cyber Security Incident Response Team (Nam-CSIRT) confirmed a cyberattack on the Ministry of Defence and Veterans Affairs, linked to the ransomware group RansomHouse. The attack involved unauthorized activity within the ministry's network, with RansomHouse threatening to release stolen information.…