Scworld
Storm-0249 Exploits EDRs for Covert Malware Attacks
First seen 11 Dec 2025, 02:49 UTC
•
•88% similarity
•30.6
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Initial access broker Storm-0249 is exploiting endpoint detection and response solutions, specifically SentinelOne, to execute stealthy malware attacks. The group has shifted from mass phishing tactics to more advanced methods, utilizing malicious curl commands and PowerShell scripts to gain SYSTEM privileges and establish persistence for ransomware operations.
ThreatCluster AI
How this analysis works