Storm-0249 Exploits EDRs for Covert Malware Attacks

Storm-0249 Exploits EDRs for Covert Malware Attacks

First seen 11 Dec 2025, 02:49 UTC BleepingcomputerScworld 88% similarity 30.6

Article Content

Browse articles
ThreatCluster

Initial access broker Storm-0249 is exploiting endpoint detection and response solutions, specifically SentinelOne, to execute stealthy malware attacks. The group has shifted from mass phishing tactics to more advanced methods, utilizing malicious curl commands and PowerShell scripts to gain SYSTEM privileges and establish persistence for ransomware operations.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story