Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-security-bypassransomware-group-operationinitial-access-methodpersistence-method

Storm-0249 Uses EDR Abuse and ClickFix for Stealthy Ransomware Deployment

Updated 3mo agoFirst seen Dec 9, 20253 sources

Storm-0249, an initial access broker previously known for selling access to compromised networks, has adopted advanced techniques to facilitate ransomware attacks. The group now leverages social engineering tactics such as ClickFix, which tricks users into executing malicious commands via the Windows Run dialog. These commands use legitimate utilities like curl.exe to download and execute fileless PowerShell scripts from spoofed Microsoft domains, ultimately deploying malicious MSI packages with SYSTEM privileges. The attack chain includes DLL sideloading, where a trojanized DLL is placed alongside legitimate EDR components (notably SentinelOne's SentinelAgentWorker.exe), allowing the attacker's code to run within trusted processes and evade detection. Once persistence is established, Storm-0249 abuses EDR tools to collect system information and maintain stealthy access, making detection and remediation challenging for defenders.

This evolution in Storm-0249's tactics demonstrates a shift from mass phishing to highly targeted, stealthy operations that exploit trusted security software for malicious purposes. The abuse of EDR solutions not only enables the bypassing of traditional security controls but also provides a reliable foothold for ransomware deployment. Security researchers recommend implementing robust email filtering, monitoring for unusual use of legitimate utilities, and updating detection rules to identify these advanced techniques. Organizations are urged to review their EDR configurations and monitor for signs of DLL sideloading and unauthorized PowerShell activity to mitigate the risk posed by this threat actor.

Share:
Storm-0249 Uses EDR Abuse and ClickFix for Stealthy Ransomware Deployment
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Dec 10, 20257mo ago

Researchers warn EDR abuse technique could spread beyond SentinelOne

Security reporting highlighted that Storm-0249's use of trusted EDR components and Windows utilities is adaptable to other endpoint security products, raising concern that similar stealth techniques may be adopted more broadly. Defenders were urged to rely more on behavioral detection, baselining, DNS monitoring, and tighter controls on LoLBins and scripting tools.

Dec 9, 20257mo ago

Researchers reveal Storm-0249 collects system IDs for ransomware deployment

Analysis of the intrusion chain showed the attacker harvesting identifiers such as MachineGuid and other hardware-linked values from compromised systems. These identifiers are used to profile victims and support ransomware deployment workflows, including binding encryption to specific machines.

Storm-0249 abuses SentinelOne EDR via DLL sideloading and fileless PowerShell

In attacks analyzed by ReliaQuest, Storm-0249 used malicious curl commands, an MSI installer, in-memory PowerShell, and DLL sideloading to execute malware through trusted SentinelOne processes and evade detection. The activity established persistence and encrypted command-and-control while blending into legitimate system activity.

Storm-0249 shifts from broad phishing to targeted intrusion tactics

Storm-0249 evolved from broad phishing campaigns to more targeted attacks using domain spoofing, ClickFix-style social engineering, and living-off-the-land techniques to gain initial access for ransomware operations. Multiple reports describe this as a tactical escalation in how the group operates.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Threat actors
1 linked
Affected products
3 linked
Windows InstallerWindowsPowershell
Organizations
6 linked
ReliaQuestMicrosoft CorporationSentinelOneStorm-0249LockBitALPHV/BlackCat
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Storm-0249 Uses EDR Abuse and ClickFix for Stealthy Ransomware Deployment | Mallory