• News/
  • https://www.bleepingcomputer.com/news/security/ransomware-iab-abuses-edr-for-stealthy-malware-execution/

Ransomware IAB abuses EDR for stealthy malware execution

BleepingComputer
·
Bill Toulas
·
Published Dec 9, 2025
·
Updated

An initial access broker tracked as Storm-0249 is abusing endpoint detection and response solutions and trusted Microsoft Windows utilities to load malware, establish communication, and persistence in preparation for ransomware attacks. The threat actor has moved beyond mass phishing and adopted stealthier, more advanced methods that prove effective and difficult for defenders to counter, even if well documented. In one attack analyzed by researchers at cybersecurity company ReliaQuest, Storm-0249 leveraged the SentinelOne EDR components to hide malicious activity. However, researchers say that the same method works with other EDR products, as well. ReliaQuest says that the Storm-0249 attack started with ClickFix social engineering that tricked users into pasting and executing curl commands in the Windows Run dialog to download a malicious MSI package with SYSTEM privileges. A malicious PowerShell script is also fetched from a spoofed Microsoft domain, which is piped straight onto the system's memory, never touching the disk and thus evading antivirus detection. The MSI file drops a malicious DLL (SentinelAgentCore.dll). According to the researchers, "this DLL is placed strategically alongside the pre-existing, legitimate SentinelAgentWorker.exe, which is already installed as part of the victim's SentinelOne EDR." Next, the attacker loads the DLL using the signed SentinelAgentWorker (DLL sideloading), executing the file within the trusted, privileged EDR process and obtainin...

Read full article

Affected Software

2 affected components
SentinelOne EDR
Microsoft Windows

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how the ransomware group IAB, identified as Storm-0249, is exploiting endpoint detection and response tools for stealthy malware execution.

2

What security implications are discussed?

The article highlights the increased risk of ransomware attacks due to the abuse of trusted security software and utilities for malicious purposes.

3

What products or software are affected?

The affected products mentioned include SentinelOne EDR and Microsoft Windows.

4

How does Storm-0249 execute malware stealthily?

Storm-0249 uses endpoint detection and response solutions combined with legitimate Microsoft utilities to load and maintain malware covertly.

5

What tactics has Storm-0249 shifted away from?

Storm-0249 has moved beyond mass phishing and adopted more sophisticated methods for infiltrating systems.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203