Threat Group: Storm-2460
Threat Type: Modular Malware, Zero-Day Exploitation, Ransomware Deployment
Exploited Vulnerabilities: CVE-2025-29824 (CLFS Use-After-Free), CVE-2025-24983 (Win32k Use-After-Free), CVE-2023-28252 (CLFS Out-of-Bounds Write)
Malware Used: PipeMagic Trojan
Threat Score: 8.4/10 – 🔴 High (due to exploitation of multiple zero-days, advanced evasion techniques, and association with ransomware families like RansomEXX and