Skip to content
Storm-0249 Exploits EDRs for Covert Malware Attacks

Storm-0249 Exploits EDRs for Covert Malware Attacks

First seen 11 Dec 2025, 02:49 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Initial access broker Storm-0249 is exploiting endpoint detection and response solutions, specifically SentinelOne, to execute stealthy malware attacks. The group has shifted from mass phishing tactics to more advanced methods, utilizing malicious curl commands and PowerShell scripts to gain SYSTEM privileges and establish persistence for ransomware operations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 200d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Alphv and SentinelOne in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed