Tuesday, September 15, 2026

PipeMagic Malware Imitates ChatGPT App to Exploit Windows Vulnerability and Deploy Ransomware

The PipeMagic malware, which is credited to the financially motivated threat actor Storm-2460, is a remarkable illustration of how cyber dangers are always changing. It poses as the genuine open-source ChatGPT Desktop Application from GitHub.

This sophisticated modular backdoor facilitates targeted attacks by exploiting CVE-2025-29824, an elevation-of-privilege vulnerability in the Windows Common Log File System (CLFS).

Microsoft Threat Intelligence identified PipeMagic during investigations into attack chains where adversaries used certutil to download a malicious MSBuild file from compromised legitimate websites, leading to in-memory execution of the backdoor.

Once deployed, PipeMagic enables privilege escalation and ransomware deployment across sectors including IT, finance, and real estate in regions like the United States, Europe, South America, and the Middle East.

Enables Zero-Day Exploitation

The malware’s architecture emphasizes flexibility and persistence, dynamically loading payloads via a dedicated networking module for command-and-control (C2) communication over TCP, while employing encrypted inter-process communication through named pipes to evade detection.

PipeMagic initializes with a 16-byte random bot identifier and spawns a thread to create a bidirectional named pipe formatted as ‘\.\pipe\1.<Bot ID hex string>’, allowing continuous payload delivery.

PipeMagic Malware
Bot ID generation

Incoming modules are decrypted using a hardcoded 32-byte RC4 key, validated via SHA-1 hashing, and stored in a doubly linked list structure.

The malware maintains four such lists: one for raw payload modules in PE format, another for executable modules loaded into memory, a network list for C2 handling, and an unknown list possibly for dynamic payload staging.

Configuration data, including a now-disabled C2 domain (aaaaabbbbbbb.eastus.cloudapp.azure.com:443), is parsed to manage operations, with fallback to local loopback for testing.

The embedded network module, XOR-decrypted and decompressed via aPLib, establishes TCP connections, exporting functions for data transmission and termination, while limiting attempts to five per session.

Advanced Capabilities

Upon C2 connection, PipeMagic collects extensive system information such as bot ID, OS version, process details, integrity levels, and domain affiliations and transmits it via HTTP GET requests with randomized paths.

Responses are processed through outer commands that trigger inner backdoor functionalities, enabling module management, data manipulation, process enumeration, and self-deletion.

For instance, processing code 0x1 handles core operations like inserting, reading, writing, or deleting modules in payload and execute lists, with arguments for indices, offsets, hashes, and encryption.

PipeMagic Malware
Extracting configuration

Similar commands interact with the unknown list for resizing or extraction, suggesting auxiliary roles in modular extensibility.

Backdoor codes provide granular control, from retrieving metadata and renaming executables to recollecting system data or interfacing with named pipes for encrypted payload exchanges.

To counter this threat, organizations should enable tamper protection, network protection, and EDR in block mode within Microsoft Defender for Endpoint, alongside automated investigation and cloud-delivered protections.

Microsoft Defender Antivirus detects PipeMagic as Win32/64 variants, with alerts for malware detection, prevention, and ransomware-linked activities.

Vulnerability management tools highlight CVE-2025-29824 exposure, while Microsoft Security Copilot offers promptbooks for incident investigation, user analysis, and threat profiling.

Threat analytics reports detail exploitation patterns, emphasizing the need for resilient defenses to disrupt adversary TTPs and raise operational costs.

Indicators of compromise

IndicatorTypeDescription
aaaaabbbbbbb.eastus.cloudapp.azure[.]com:443DomainPipeMagic’s C2 domain
dc54117b965674bad3d7cd203ecf5e7fc822423a3f692895cf5e96e83fb88f6aFile SHA-256 hashIn-memory dropper (trojanized ChatGPT desktop application)
4843429e2e8871847bc1e97a0f12fa1f4166baa4735dff585cb3b4736e3fe49eFile SHA-256 hashPipeMagic backdoor (unpacked in memory)
297ea881aa2b39461997baf75d83b390f2c36a9a0a4815c81b5cf8be42840fd1File SHA-256 hashPipeMagic network module (unpacked in memory)

Find this News Interesting! Follow us on Google News, LinkedIn, and X to Get Instant Updates!

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor

China-linked threat actors tracked as UNC3569 have exploited a...

Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users

A Casbaneiro banking Trojan campaign targeting users across Latin...

AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process

A five-stage AsyncRAT campaign that chains a socially engineered...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

Related Articles

Recent News