Storm-0249 is now abusing trusted endpoint detection and response tools to run malware in ways that blend in with normal system activity. Researchers at ReliaQuest found that the group uses SentinelOne components as a disguise that allows malicious DLLs and PowerShell payloads to run without detection. The activity hides inside a signed and privileged EDR process, which gives attackers persistence that survives system changes. The method works against any defender that relies heavily on traditional monitoring instead of behavior analytics.
Relevant Source (The Hacker News): Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading
This article describes how Storm-0249 has shifted from phishing to abusing EDR tools, using DLL sideloading, fileless PowerShell, and legitimate utilities to stealthily prepare ransomware attacks.
Quick Facts
- Storm-0249 is an initial access broker that sells entry points to ransomware crews.
- The group now uses EDR components like SentinelOne to execute malware covertly.
- Victims were tricked into pasting curl commands that install a malicious MSI package.
- Attackers load a rogue DLL through trusted EDR processes using DLL sideloading.
- Activity blends into normal SentinelOne behavior so most tools ignore it.
- Admins should tighten curl, PowerShell, and LoLBin controls and use behavior-based alerts.
Inside Storm-0249 Attack Chain
Storm-0249 uses social engineering to funnel users into running curl commands that install an MSI package with high privilege. The package fetches a PowerShell script directly into memory so no files land on disk. The MSI then plants a malicious SentinelAgentCore.dll next to the legitimate SentinelAgentWorker.exe that already exists within SentinelOne’s directory. The attacker sideloads the DLL through the signed executable, so the malicious payload runs under a trusted process.
- MSI installs a malicious DLL beside legitimate SentinelOne components.
- DLL sideloading forces a trusted executable to run attacker code.
- Memory-only PowerShell delivery avoids antivirus scanning.
This approach gives attackers a stealthy foothold that rarely triggers alarms because the EDR process looks genuine. The behavior blends into routine background operations that defenders usually trust.
Relevant Source (Huntress): Cephalus Ransomware: Don’t Lose Your Head
This Huntress analysis shows how Cephalus ransomware abuses legitimate SentinelOne executables for DLL sideloading and PowerShell-based actions, closely mirroring the trusted-process abuse and sideloading behavior described in this section.
Why EDR Abuse Works
Storm-0249 targets EDR tools because security teams rely on them as a single source of truth. Running inside a trusted security process shields suspicious behavior from many monitoring layers. System commands like reg.exe and findstr.exe look normal when sourced from an EDR component, which allows attackers to gather system identifiers and build profiles for ransomware affiliates.
- Hides malicious actions inside a signed, privileged process.
- Evades antivirus because payloads never touch disk.
- Enables encrypted C2 traffic without raising alerts.
- Lets attackers collect MachineGuid values for ransomware encryption.
- Provides durable persistence across updates.
The method helps ransomware crews gain stable, low-noise access to targets. It also delays detection long enough for encryption or extortion stages to begin.
Relevant Source (CrowdStrike): 4 Ways Adversaries Hijack DLLs
This article explains how attackers use DLL hijacking to run malicious code inside legitimate, signed processes for defense evasion, persistence, and privilege escalation, which mirrors why abusing trusted EDR components is so effective.
Detect & Lock Down Risky Tools
Defenders need controls that focus on behavior rather than trusting signed binaries by default. Systems should alert when a well-known process loads unsigned DLLs from unusual paths. Loosely governed tools like curl, PowerShell, and Windows LoLBins should be restricted or monitored more aggressively to stop memory-only payloads.
Suggested actions include:
- Block or restrict curl usage on endpoints.
- Limit PowerShell to signed scripts or constrained modes.
- Alert when trusted executables load new DLLs.
- Monitor LoLBin activity from atypical parent processes.
- Review EDR baselines for suspicious deviations.
Stronger monitoring and tighter scripting controls reduce the blind spots Storm-0249 exploits. Small policy changes make it easier to catch the behavior before ransomware deploys.
Relevant Source (CISA): Identifying and Mitigating Living-Off-the-Land Techniques
This Ransomware & Cybersecurity Advisory details how attackers use built-in system tools like PowerShell, LoLBins, and DLL sideloading to evade detection, and recommends restricting or closely monitoring those tools as part of a layered defense.
Ransomware Ecosystem Keeps Evolving
Initial access brokers are refining their methods because ransomware groups pay for reliable entry points. Storm-0249’s shift from broad phishing to targeted EDR abuse shows that attackers want low-noise techniques that blend in with enterprise security tools. This puts pressure on defenders to rethink assumptions about trusted processes and certificates. Signed binaries are not always safe when they become loaders for unsigned code.
EDR vendors continue to improve detection, but attackers are adapting faster by hiding inside the very tools designed to stop them. Behavioral analytics and strict execution policies have become essential because signature-based trust alone gives attackers room to maneuver. Organizations need layered controls that can catch strange loading patterns even when the parent process appears legitimate.
Relevant Source (Center for Internet Security): Initial Access Brokers How They’re Changing Cybercrime
This CIS blog explains how initial access brokers fuel modern ransomware operations and why their evolving tactics force organizations to adopt layered, behavior-focused defenses.
Move Beyond Signature Trust
Storm-0249’s technique shows that defenders cannot rely on trusted signatures alone. Behavioral cues, DLL loading patterns, and script restrictions must play a larger role. Security teams that adjust now will reduce the window attackers use to stage ransomware operations.
Relevant Source (SentinelOne): Signature-Based vs. Behavior-Based Detection
This article details why signature-based detection alone fails against modern threats and argues behavior- or AI-based detection is needed to catch stealthy attacks like DLL sideloading and fileless malware.
FAQ
How does Storm-0249 get users to run the initial command?
They use ClickFix-style prompts that trick users into pasting curl commands into the Windows Run dialog.
Why does antivirus miss the attack?
The payload loads directly into memory through PowerShell and executes inside a trusted EDR process, bypassing file-based scanning.
Does this only affect SentinelOne?
No. Researchers say the method can work with other EDR tools that rely on signed executables located beside loadable DLLs.
Why do attackers collect MachineGuid?
Ransomware groups use it to create victim-specific encryption keys that prevent easy recovery.
What is the strongest immediate defense?
Monitor for trusted processes loading unsigned DLLs and restrict risky tools like curl and PowerShell.
How JENI Strengthens Endpoint Security
Modern attacks that hide inside trusted processes expose a weak point that many organizations overlook. Systems fail when cleanup, repair, and monitoring controls fall behind real-world threat behavior. JENI helps close that gap by keeping endpoints stable, predictable, and free of system errors that attackers often rely on.
What JENI Supports
- Removes corrupted caches, temp files, and logs attackers may exploit
- Repairs core system services that malware often hides behind
- Improves endpoint stability so abnormal behavior stands out faster
Stronger baselines make stealthier threats easier to detect because odd activity no longer hides in a pile of system junk. Clean, stable environments force malicious actions to become more obvious to defenders and security tools. Reliable maintenance reduces blind spots that initial access brokers take advantage of. JENI helps keep endpoints healthy so defenders can focus on actual threats instead of fighting through noise.

