

Threat Landscape Update: Ransomware-as-a-Service and Advanced Modular Malware
Oct 8, 2025
Chuong Dong, a security engineer and malware expert at Microsoft, dives deep into the threat landscape of ransomware and modular malware. He discusses PipeMagic, a sophisticated backdoor masquerading as a harmless desktop app, and its detection challenges. The conversation shifts to Medusa ransomware and its transition to a ransomware-as-a-service model using double extortion tactics. Dong highlights the abuse of legitimate tools in these attacks and the crucial role of leak sites in ransomware operations. Tune in for vital insights into modern cybersecurity threats!
AI Snips
Chapters
Transcript
Episode notes
Targeted Use Of Exploited Vulnerability
- Storm 2460 used PipeMagic after exploiting CVE‑2025‑29824 to deploy ransomware.
- Targets span IT, finance, real estate and regions including the US, Europe and South America.
Modular Backdoor Self‑Updating In Memory
- PipeMagic is a modular backdoor that updates itself in memory by receiving modules from a C2 server.
- This design lets operators change capabilities on the fly, making detection and attribution harder.
Malware Is Far From Over
- Malware remains prolific despite claims it is declining; actors keep innovating monetization methods.
- Researchers expect malware and exploit development to continue growing, not disappearing.