An initial access broker tracked as Storm-0249 is abusing endpoint detection and response solutions and trusted Microsoft Windows utilities to load malware, establish communication, and persistence in preparation for ransomware attacks. The threat actor has moved beyond mass phishing and adopted stealthier, more advanced methods that prove effective and difficult for defenders to counter, even if well documented. In one attack analyzed by researchers at cybersecurity company ReliaQuest, Storm-0249 leveraged the SentinelOne EDR components to hide malicious activity. However, researchers say that the same method works with other EDR products, as well. ReliaQuest says that the Storm-0249 attack started with ClickFix social engineering that tricked users into pasting and executing curl commands in the Windows Run dialog to download a malicious MSI package with SYSTEM privileges. A malicious PowerShell script is also fetched from a spoofed Microsoft domain, which is piped straight onto the system's memory, never touching the disk and thus evading antivirus detection. The MSI file drops a malicious DLL (SentinelAgentCore.dll). According to the researchers, "this DLL is placed strategically alongside the pre-existing, legitimate SentinelAgentWorker.exe, which is already installed as part of the victim's SentinelOne EDR." Next, the attacker loads the DLL using the signed SentinelAgentWorker (DLL sideloading), executing the file within the trusted, privileged EDR process and obtainin...
Ransomware IAB abuses EDR for stealthy malware execution
BleepingComputer
·Bill Toulas
·Published Dec 9, 2025
·Updated
Affected Software
2 affected components
SentinelOne EDR
Microsoft Windows
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how the ransomware group IAB, identified as Storm-0249, is exploiting endpoint detection and response tools for stealthy malware execution.
2
What security implications are discussed?
The article highlights the increased risk of ransomware attacks due to the abuse of trusted security software and utilities for malicious purposes.
3
What products or software are affected?
The affected products mentioned include SentinelOne EDR and Microsoft Windows.
4
How does Storm-0249 execute malware stealthily?
Storm-0249 uses endpoint detection and response solutions combined with legitimate Microsoft utilities to load and maintain malware covertly.
5
What tactics has Storm-0249 shifted away from?
Storm-0249 has moved beyond mass phishing and adopted more sophisticated methods for infiltrating systems.